Communal Device Progressive Access via Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user authentication methods on communal computing devices, such as interactive digital whiteboards and public kiosks, are either insecure or require additional hardware and processor usage, particularly due to the need for biometric enrollment and storage of sensitive data.

Innovation Solution

Establishing a trust relationship between the communal computing device and a cloud-based provider, allowing users to authenticate using their personal devices, which reduces processor usage and enhances security by leveraging low-fidelity identification data stored on the cloud, enabling progressive levels of access based on identification and authentication signals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric security is implemented on communal computing devices, then user authentication security and convenience are improved, but device complexity and processor usage increase due to specialized hardware and enrollment requirements

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based service as an intermediary that handles biometric authentication processing. Instead of implementing biometric hardware and processing capabilities directly on the communal computing device, the system uses a cloud service to perform the authentication, allowing the device to leverage biometric security without the associated hardware complexity and enrollment overhead

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of implementing local biometric hardware and processing on the communal device with a network-based solution. By substituting the physical authentication mechanism with a cloud-based service, the system achieves biometric security without requiring specialized hardware or complex local processing capabilities

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Speed

If biometric data is stored on the communal computing device, then authentication speed is improved, but security is worsened due to the shared nature of communal devices

Engineering Contradiction:
Improveauthentication speedVSAvoiddata security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The cloud-based service acts as an intermediary that securely stores and processes biometric data. The communal device communicates authentication requests to the cloud service, which performs the verification and returns results. This eliminates the need for the communal device to store sensitive biometric data locally while maintaining fast authentication through optimized cloud processing

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves the biometric data storage and processing from the local dimension (on the communal device) to the cloud dimension (remote server). By transitioning authentication data management to a different spatial and architectural dimension, the system achieves both fast authentication through dedicated cloud infrastructure and enhanced security through centralized control and encryption

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Device complexity

If passwords are used for authentication on communal computing devices, then device complexity is reduced, but security is worsened and user convenience is reduced due to cumbersome entry requirements

Engineering Contradiction:
Improvedevice complexityVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces the mechanical keyboard input method for password entry with a camera-based optical recognition system. The camera captures an image of the user typing on their personal device, and the system optically recognizes the password being entered. This substitution eliminates the need for physical keyboards on communal devices while enhancing security by allowing secure password entry without exposing it to public view

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

Instead of requiring direct physical interaction with the communal device for authentication, the system creates a visual copy of the authentication process. The camera captures the user's typing actions on their personal device, creating an optical copy of the password entry that can be recognized and verified without the user actually typing on the communal device

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3864541B1Progressive access to data and device functionality
Publication Date: 2023.06.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3864541B1 patent drawingFigure 1
  • EP3864541B1 patent drawingFigure 2
  • EP3864541B1 patent drawingFigure 3

AI summary

A communal computing device such as an interactive digital whiteboard can provide progressively more access to functionality and data on the device based on a level of certainty in the identity of a user. If a user is identified based on one or more low-fidelity identification signals such as an image of the user or a device identifier, the communal computing device may provide a first level of functionality that is limited. If the user requests greater access, the communal computing device can request that a trusted cloud-based provider authenticate the user by way of a personal device, such as a smartphone. The authentication may be a password or high-fidelity biometric identification. The cloud-based provider communicates successful authentication to the communal computing device and it, in turn, provides the user access to higher, second level of functionality.