Combined Authorization Process for Secure Device Group Joining
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users with multiple devices that share overlapping functionalities face inefficiencies in data transfer and synchronization, relying on methods like flash memory sticks and email, necessitating more efficient techniques for automatic data sharing across devices.
Innovation Solution
A method allowing a device to join a group of related devices for synchronized data sharing with a centralized entity using a single process, requiring minimal user inputs, while ensuring encrypted data security and unified access through a cloud services account, utilizing a combined authorization and synchronization process that includes generating and verifying random codes to prevent malicious access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional data transfer methods (flash memory sticks, email) are used to share data between devices, then data transfer is achieved, but the process is inefficient and requires manual intervention
Solution Approach 1:
The system enables automatic data synchronization between devices without requiring manual intervention. When a user authenticates a new device, the system automatically adds it to the synchronization group and enables data sharing, eliminating the need for users to manually transfer files via flash memory or email.
Solution Approach 2:
The patent combines multiple functions into a single authentication process: device authorization, group joining, and data synchronization initiation all occur during one authentication flow. This merging eliminates the need for separate manual data transfer operations and streamlines the user experience.
2Ease of operation
If a single process is used for both authorization and synchronization group joining, then user input requirements are reduced, but the process complexity increases
Solution Approach 1:
The authentication process is segmented into distinct phases: (1) user provides password and device code, (2) system verifies credentials and generates a shared secret, (3) system automatically adds device to synchronization group. This segmentation allows complex operations to be broken down into manageable steps while presenting a simplified interface to the user.
Solution Approach 2:
The patent introduces intermediary components including a shared secret key generated during authentication and a synchronization server that mediates between devices. These intermediaries handle the complexity of coordinated authentication and group management, allowing the user interface to remain simple while the backend processes remain sophisticated.
3Reliability
If encrypted data synchronization is implemented with centralized authority involvement, then data security is improved, but the risk of centralized point of failure increases
Solution Approach 1:
The patent extracts critical cryptographic operations from the centralized authority. Devices generate their own shared secrets and authentication codes locally, and the synchronization server only facilitates the process without storing sensitive credentials. This extraction reduces the impact of centralized authority compromise while maintaining security.
Solution Approach 2:
The system changes the cryptographic parameters and key management approach by using ephemeral shared secrets generated during each authentication session rather than persistent master keys held by the centralized authority. This parameter change ensures that even if the centralized server is compromised, long-term data security remains intact.
4Reliability
If random codes are generated and verified to prevent malicious access, then security against malicious centralized entity is improved, but the authentication process time increases
Solution Approach 1:
The system performs preliminary actions by pre-establishing authentication mechanisms and generating random codes in advance. The synchronization server prepares verification routines and shared secret generation algorithms before actual authentication occurs, enabling rapid verification when users authenticate devices without time-consuming real-time computations.
Data Source
AI summary
Some embodiments provide a method for a first device to join a group of related devices. The method receives input of a password for an account with a centralized entity and a code generated by a second device in the group. When the second device determines that the code input on the first device matches the generated code, the method receives an authentication code from the second device for authorizing the first device with the entity as a valid device for the account. The method uses the password and information regarding the first device to generate an application to the group. After sending the application to the second device, the method receives information from the second device that enables the first device to add itself to the group. The second device verifies the generated application, and the method uses the information received from the second device to join the group.


