Authentication Context Sharing Across Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network service providers face challenges in delivering convenience and security as traditional authentication methods require repeated authentication processes for different applications on the same device, leading to wasted network resources and diminished user experience.

Innovation Solution

A system that shares authentication session information between applications by receiving and storing an authentication context in a cache associated with one service and populating it into another cache associated with a different service, allowing seamless access without additional authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for each application, then security is maintained, but network resources are wasted and user experience is diminished due to repeated authentication processes

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges authentication contexts across different applications by storing the authentication context in a first cache associated with a first service and populating it into a second cache associated with a second service. This allows authentication information to be shared between applications, eliminating redundant authentication processes and conserving network resources while maintaining security through centralized authentication context management

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If traditional authentication methods are used for each application, then security is maintained, but user experience is diminished due to repeated authentication processes

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges authentication contexts across different applications by storing the authentication context in a first cache associated with a first service and populating it into a second cache associated with a second service. This allows authentication information to be shared between applications, eliminating redundant authentication processes and conserving network resources while maintaining security through centralized authentication context management

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If authentication context is stored in a cache and populated to another service, then authentication efficiency is improved, but device complexity increases due to cache management mechanisms

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidcache management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism where the interface stores authentication contexts in a first cache and populates them to a second cache associated with different services. This intermediary cache management system enables efficient authentication context sharing across applications while centralizing the complexity of cache management within the interface rather than distributing it across all applications

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3917106B1Method and apparatus for providing authentication session sharing
Publication Date: 2023.05.31 NOKIA TECHNOLOGIES OY
  • EP3917106B1 patent drawingFigure 1
  • EP3917106B1 patent drawingFigure 2
  • EP3917106B1 patent drawingFigure 3

AI summary

An apparatus comprising means for performing receiving (315), at an interface, an authentication context associated with a first service; causing (317), at least in part, storage of the authentication context in a first cache associated with the interface; and causing (319), at least in part, population of a converted version of the authentication context to a second cache associated with a second service, wherein the converted version of the authentication context in the second cache authenticates access to the second service.