Cloud Credential Management for Shared Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based computing solutions, users face issues when sharing devices as temporary users, leading to unexpected behavior of applications and services due to retained login credentials, requiring manual logout and login upon device return.

Innovation Solution

Implementing automated credential management that allows temporary users to log into client device applications seamlessly while ensuring original users can log back in after predetermined criteria are met, such as session end or time out, by unbinding and re-binding credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If login credentials are retained in client device applications for cloud account access, then user convenience is improved, but security and privacy are worsened when devices are shared

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity and privacy risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system dynamically manages login credentials by automatically detecting device sharing conditions and adjusting credential binding states accordingly. When a device is identified as shared, the system dynamically unbinds credentials from the shared device while maintaining them for the owner's devices, thus adapting the security state based on real-time usage conditions

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system introduces an intermediary credential management mechanism that acts as a mediator between the user's cloud account and client device applications. This intermediary layer automatically binds or unbinds credentials based on device sharing detection, eliminating the need for manual user intervention while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual logout and login is required when returning shared devices, then security is improved, but user burden and time loss increase

Engineering Contradiction:
ImprovesecurityVSAvoidtime for manual logout and login
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by proactively detecting when a device has been returned to the owner and automatically re-binding login credentials before the user needs to access applications. This preliminary credential restoration eliminates the need for manual logout/login operations when devices are returned

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by automatically monitoring device sharing status and managing credential binding without requiring user intervention. The system autonomously handles credential unbinding when devices are shared and re-binding when devices are returned, saving user time and effort

Inventive Principle:
Principle #25Self-service

3Ease of operation

If automated credential binding and unbinding is implemented, then user burden is reduced, but system complexity increases

Engineering Contradiction:
Improveuser burden reductionVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system introduces an intermediary credential management service that automatically binds or unbinds credentials based on device sharing detection. This intermediary layer handles the complexity of automated credential management internally, presenting a simple interface to users while managing sophisticated binding/unbinding logic in the background

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9413770B2Cloud based application account management
Publication Date: 2016.08.09 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US9413770B2 patent drawing
  • US9413770B2 patent drawing
  • US9413770B2 patent drawing

AI summary

An aspect provides a method, including: receiving at a remote device a client log in to a cloud based account issued from a client device; determining the client device is not associated with the client log in; issuing an instruction to unbind at least one client device application log in credential and bind a cloud client log in credential to the at least one client device application; and providing an instruction to unbind the cloud client log in credential from the at least one client device application in response to at least one predetermined criteria being satisfied. Other aspects are described and claimed.