Communal Device Progressive Access via Cloud Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current user authentication methods on communal computing devices, such as interactive digital whiteboards and public kiosks, are either insecure or require additional hardware and processor usage, particularly due to the need for biometric enrollment and storage of sensitive data.
Innovation Solution
Establishing a trust relationship between the communal computing device and a cloud-based provider, allowing users to authenticate using their personal devices, which reduces processor usage and enhances security by leveraging low-fidelity identification data stored on the cloud, enabling progressive levels of access based on identification and authentication signals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric security is implemented on communal computing devices, then user authentication security and convenience are improved, but device complexity and processor usage increase due to specialized hardware and enrollment requirements
Solution Approach 1:
The patent introduces a cloud-based service as an intermediary that handles biometric authentication processing. Instead of implementing biometric hardware and processing capabilities directly on the communal computing device, the system uses a cloud service to perform the authentication, allowing the device to leverage biometric security without the associated hardware complexity and enrollment overhead
Solution Approach 2:
The patent replaces the mechanical approach of implementing local biometric hardware and processing on the communal device with a network-based solution. By substituting the physical authentication mechanism with a cloud-based service, the system achieves biometric security without requiring specialized hardware or complex local processing capabilities
2Speed
If biometric data is stored on the communal computing device, then authentication speed is improved, but security is worsened due to the shared nature of communal devices
Solution Approach 1:
The cloud-based service acts as an intermediary that securely stores and processes biometric data. The communal device communicates authentication requests to the cloud service, which performs the verification and returns results. This eliminates the need for the communal device to store sensitive biometric data locally while maintaining fast authentication through optimized cloud processing
Solution Approach 2:
The patent moves the biometric data storage and processing from the local dimension (on the communal device) to the cloud dimension (remote server). By transitioning authentication data management to a different spatial and architectural dimension, the system achieves both fast authentication through dedicated cloud infrastructure and enhanced security through centralized control and encryption
3Device complexity
If passwords are used for authentication on communal computing devices, then device complexity is reduced, but security is worsened and user convenience is reduced due to cumbersome entry requirements
Solution Approach 1:
The patent replaces the mechanical keyboard input method for password entry with a camera-based optical recognition system. The camera captures an image of the user typing on their personal device, and the system optically recognizes the password being entered. This substitution eliminates the need for physical keyboards on communal devices while enhancing security by allowing secure password entry without exposing it to public view
Solution Approach 2:
Instead of requiring direct physical interaction with the communal device for authentication, the system creates a visual copy of the authentication process. The camera captures the user's typing actions on their personal device, creating an optical copy of the password entry that can be recognized and verified without the user actually typing on the communal device
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A communal computing device such as an interactive digital whiteboard can provide progressively more access to functionality and data on the device based on a level of certainty in the identity of a user. If a user is identified based on one or more low-fidelity identification signals such as an image of the user or a device identifier, the communal computing device may provide a first level of functionality that is limited. If the user requests greater access, the communal computing device can request that a trusted cloud-based provider authenticate the user by way of a personal device, such as a smartphone. The authentication may be a password or high-fidelity biometric identification. The cloud-based provider communicates successful authentication to the communal computing device and it, in turn, provides the user access to higher, second level of functionality.