Centralized Device Authentication with Context-Based Trust Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online authentication techniques are piecemeal and independent, causing user confusion and reduced security due to the need for multiple usernames and passwords, and limitations of cookie-based authentication.
Innovation Solution
Implement a centralized identification service that maintains device profiles and activity information to provide authentication information to online services, using device profiles and activity data to determine authentication levels, allowing services to grant access without additional user input.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If independent authentication is used for each online service, then each service can maintain its own security standards, but users must remember multiple usernames and passwords causing confusion and reduced security
Solution Approach 1:
The patent merges multiple independent authentication systems into a single centralized authentication service. The authentication service receives authentication information from the user and generates authentication tokens that are shared across multiple online services, eliminating the need for users to remember multiple credentials while maintaining security through centralized control and token-based verification.
Solution Approach 2:
The authentication service provides universal authentication capabilities across different online services. A single authentication credential issued by the centralized service can be used to access multiple services, making the authentication system multi-functional and eliminating the need for service-specific authentication mechanisms.
2Ease of operation
If users use the same usernames and passwords across services to simplify authentication, then ease of operation improves, but reliability and security of authentication decrease
Solution Approach 1:
The patent introduces an intermediary authentication service that acts as a mediator between the user and multiple online services. Instead of users directly managing credentials for each service, the authentication service generates and manages secure tokens on behalf of the user. This intermediary approach allows users to maintain convenience while the system ensures security through centralized token management and validation.
3Device complexity
If cookie-based authentication is used, then session management is simplified, but authentication reliability is reduced due to limitations of cookie storage and security
Solution Approach 1:
The patent replaces the traditional cookie-based mechanical authentication system with a token-based authentication mechanism. Instead of relying on cookies stored in the user's browser which have security and reliability limitations, the system uses secure tokens generated and managed by the centralized authentication service, providing more reliable authentication while maintaining session management capabilities.
Data Source
AI summary
Methods, apparatus, systems and articles of manufacture to implement centralized authentication for granting access to services are disclosed. Example apparatus disclosed herein to perform device authentication at a first service are to access a profile based on an identification code included in an authentication request from a second service, the profile corresponding to a device associated with the identification code, the identification code assigned to the device by the first service. Disclosed example apparatus are also to assign a selected one of a plurality of trust levels to the device based on activity information associated with the device, location information specified for the device in the profile, and mobility information specified for the device in the profile. Disclosed example apparatus are further to transmit authentication information for the device to the second service responsive to the authentication request, the authentication information including the selected one of the trust levels.


