Centralized Authentication Server for Multi-Device Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users must individually log into multiple devices managed by different authentication services using different credential information, requiring multiple authentication devices, which is inconvenient and requires downtime for maintenance updates.

Innovation Solution

An authentication server connected to multiple client devices via a network, storing user and credential information, and sending the required credential information to each device for seamless login, including the option to create pseudo credentials when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users carry multiple authentication devices to access different services, then authentication capability is improved, but device complexity and user convenience deteriorate

Engineering Contradiction:
Improveauthentication capabilityVSAvoidnumber of authentication devices
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication devices into a single server system. The server stores credential information for multiple services and performs authentication centrally, replacing the need for users to carry separate authentication devices for each service.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server provides universal authentication capability across multiple services. A single server can authenticate users for different applications and services by storing and managing diverse credential information, making one device perform multiple authentication functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple authentication devices are used for different services, then service access is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveservice access capabilityVSAvoidauthentication operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authentication server acts as an intermediary between users and multiple services. Instead of users directly interacting with multiple authentication devices, the server mediates authentication requests, receiving user credentials and returning authentication results, thereby simplifying the operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication services are updated, then security is improved, but productivity deteriorates due to downtime

Engineering Contradiction:
Improveauthentication securityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication server performs preliminary actions by pre-storing credential information for multiple services in its database. This preparation allows the server to handle authentication requests immediately without needing to query external services during authentication, enabling faster updates and maintenance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11582220B2Authentication server and method that allow user to log into application or service provided via client devices
Publication Date: 2023.02.14 KONICA MINOLTA BUSINESS SOLUTIONS USA INC
  • US11582220B2 patent drawing
  • US11582220B2 patent drawing
  • US11582220B2 patent drawing

AI summary

An authentication server is connected to a plurality of client devices via a network and includes: a storage that stores a database including: a plurality of pieces of user information; and multiple kinds of a plurality of pieces of credential information for logging into an application or service provided by an external server via each of the client devices; and a processor that: upon receiving a first piece of user information from a first client device, determines whether the database contains a first piece of credential information corresponding to the first piece of user information, and upon determining that the database contains the first piece of credential information, sends to the first client device the first piece of credential information required to allow a user to log into the application or service provided via the first client device.