Aggregate Authentication Token for Multi-Device Group Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing group-based communication systems face challenges in multi-device user authentication, requiring users to perform numerous actions to enable active authentication conditions on multiple devices, which is tedious and time-consuming, and often relies on external communication devices for token transmission, compromising security and reliability.

Innovation Solution

Implementing multi-device user authentication using authentication command interfaces and limited user authentication routines that generate aggregate authentication tokens with expiration times, allowing for streamlined access across devices without the need for individual token input on each device, and enabling revocation of authentication conditions for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multi-device authentication is implemented, then security is maintained through individual token verification, but user operation complexity increases significantly requiring numerous actions on each device

Engineering Contradiction:
Improveauthentication securityVSAvoiduser operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple individual authentication tokens into a single aggregate authentication token that can authenticate across multiple devices simultaneously. This combining approach reduces the number of authentication actions users must perform while maintaining security through centralized verification of the aggregate token on the authentication server.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The aggregate authentication token is designed to serve multiple devices universally, allowing a single token to enable authentication conditions on multiple computing devices rather than requiring device-specific tokens. This multi-functional approach simplifies user operations while the server maintains control over which devices can be authenticated.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If individual authentication tokens are used on each device, then device-specific security is ensured, but the system complexity increases due to multiple token management requirements

Engineering Contradiction:
Improvedevice-specific securityVSAvoidtoken management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple individual authentication tokens are merged into a single aggregate authentication token structure that contains references to the individual tokens. This reduces token management complexity by consolidating what would otherwise require separate management of multiple tokens across different devices, while the server can still verify individual token validity when needed.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If external communication devices are used for token transmission, then ease of token sharing is improved, but security is compromised due to reliance on external devices

Engineering Contradiction:
Improvetoken transmission easeVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication server acts as an intermediary that generates and manages the aggregate authentication token, eliminating the need for users to manually transmit tokens through external communication devices. The server mediates the authentication process by directly providing authentication credentials to authorized devices, thereby maintaining security while enabling easy authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication where the authentication server automatically provides the aggregate authentication token to authorized devices without requiring manual intervention or external communication devices for token transmission. This automated approach both simplifies user operations and maintains security through server-controlled token distribution.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If authentication conditions are permanently enabled across devices, then access convenience is improved, but security control is reduced due to inability to revoke individual device access

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system implements dynamic control where the authentication server can modify authentication conditions in real-time, including enabling or disabling access for specific devices associated with the aggregate authentication token. This dynamic capability allows the system to provide convenient persistent access while maintaining the ability to revoke or modify access rights as needed, balancing convenience and security control.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11941103B2Multidevice user authentication in group-based communication systems
Publication Date: 2024.03.26 SALESFORCE INC
  • US11941103B2 patent drawing
  • US11941103B2 patent drawing
  • US11941103B2 patent drawing

AI summary

Method, apparatus and computer program product for multi-device user authentication are described herein. For example, the apparatus includes at least one processor and at least one non-transitory memory including program code. The at least one non-transitory memory and the program code are configured to, with the at least one processor, identify, on a first computing device, a first active interface session associated with one or more active authentication conditions each configured to enable access to a group-based communication interface of a group-based communication system; cause a first computing device to present an authentication command interface for the first active interface session; receive an interface session request from a second computing device indicating electronic communication by the second computing device with the authentication command interface; and cause the second computing device to execute limited user authentication routines each configured to enable a respective active authentication condition on the second computing device.