Cloud Authentication via Proximity Credential Relay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience and time consumption when accessing cloud-based services, as they often need to manually enter valid usernames and passwords, especially when these credentials are not stored on their primary communication device.

Innovation Solution

A system and method that utilize peer-to-peer ad hoc communication links to automatically retrieve and provide valid usernames and passwords from proximate communication devices, allowing seamless access to cloud-based services without the need for redundant login processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users manually enter usernames and passwords to access cloud-based services, then authentication security is maintained, but user convenience and access speed deteriorate

Engineering Contradiction:
Improveuser convenienceVSAvoidlogin time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system pre-establishes peer-to-peer ad hoc communication links between communication devices before authentication is needed. Credentials are made available in advance through these pre-established communication channels, eliminating the need for manual entry at the moment of access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces peer-to-peer ad hoc communication links as an intermediary mechanism between the user's communication device and the cloud-based service. This intermediary automatically transmits authentication credentials, replacing manual user action while maintaining secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If credentials are stored on multiple communication devices, then access availability improves, but security risk increases

Engineering Contradiction:
Improveaccess availabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system creates temporary copies of authentication credentials in the form of ad hoc communication links between devices. These copies are ephemeral and device-specific, allowing multiple devices to access services without permanently storing credentials on each device, thus maintaining security while improving availability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the state of credential storage from persistent on-device storage to temporary transmission through peer-to-peer communication links. By altering how credentials exist (as transient communication data rather than stored files), the system enables multi-device access without proportionally increasing security risks.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automatic credential retrieval via peer-to-peer links is implemented, then access speed improves, but system complexity increases

Engineering Contradiction:
Improveaccess speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal peer-to-peer ad hoc communication framework that serves multiple functions: establishing communication channels, transmitting credentials, and enabling authentication. This multi-functional approach consolidates what could be separate complex systems into a single versatile mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables communication devices to automatically establish peer-to-peer links and retrieve credentials without manual user intervention or complex centralized coordination. The devices self-organize and self-authenticate through the ad hoc network, reducing the complexity of system management while maintaining high access speed.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3550796B1Accessing a cloud-based service via authentication data delivered by another communication device
Publication Date: 2021.10.27 GOOGLE TECHNOLOGY HOLDINGS LLC
  • EP3550796B1 patent drawingFigure 1
  • EP3550796B1 patent drawingFigure 2
  • EP3550796B1 patent drawingFigure 3

AI summary

Arrangements described herein relate to accessing a cloud based service. A first device can be determined to be located proximate to a second device, wherein the first device does not have authentication data for a cloud-based service accessible via a network. Based at least in part on the determination that the first device is located proximate to the second device, a peer-to-peer ad-hoc communication link between a first device and a second device can be established. Authentication data can be received by the first device from the second device via the peer-to-peer ad-hoc communication link, wherein the authentication data was previously used by the second device to communicate with the network. The authentication data can be transmitted from the first device, via a second communication link that is different from the peer-to-peer ad-hoc communication link, to the network to authenticate the first device for the cloud-based service.