Concurrent Identity Support With Unified Cross-Device Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face complexity in managing multiple identities and authentication processes across different electronic devices running on various operating systems, necessitating separate login information for each device.
Innovation Solution
A system that leverages multiple authentication sessions using trusted identity and access management (IAM) solutions to validate a primary user identity across devices, utilizing authentication factors like OAuth, SAML, and Kerberos tokens, and maps these to a single primary token for seamless login across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication is required for each electronic device, then device security is improved, but user operation complexity increases
Solution Approach 1:
The patent merges multiple device-specific authentication credentials into a single primary identity token. The system combines authentication from multiple devices (first device, second device, third device) to generate one unified token that represents the user's identity across all devices, eliminating the need to manage separate credentials for each device.
Solution Approach 2:
The primary identity token serves multiple functions across different devices and authentication scenarios. A single token can be used to authenticate the user on any device in the group, providing universal access while maintaining security. The token can also be used for various authentication factors including passwordless authentication, biometric verification, and multi-factor authentication.
2Reliability
If multiple authentication sessions are validated across different identity systems, then authentication reliability is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary system that acts as a mediator between multiple identity systems and devices. This intermediary validates authentication sessions from different identity systems (OAuth, SAML, Kerberos) and coordinates the generation of the primary identity token, simplifying the overall system architecture while maintaining high authentication reliability.
Solution Approach 2:
The system implements a nested structure where multiple authentication sessions and identity tokens are nested within a single primary identity token. The primary token contains or references authentication information from multiple devices and identity systems, creating a hierarchical nesting that organizes complexity while maintaining security and reliability.
3Reliability
If a primary identity token is generated from multiple authentication factors, then security is improved, but authentication process time increases
Solution Approach 1:
The system performs preliminary authentication actions by pre-validating authentication sessions on multiple devices before generating the primary identity token. Authentication factors are collected and validated in advance, and the primary token is generated once all validations are complete, reducing the time required during actual authentication events.
Solution Approach 2:
The system maintains continuous authentication sessions across devices, where valid authentication states are preserved and carried forward. Once a user authenticates on one device, the authentication state continues to be valid on other devices in the group, eliminating the need for repeated authentication and reducing overall authentication time while maintaining security.
Data Source
AI summary
An apparatus can include an interface for receiving authentication tokens from a user. The apparatus can include processing circuitry coupled to the interface. The processing circuitry can receive, over the interface, a first authentication token of the user and at least a second authentication token of the user. The processing circuitry can determine whether the first authentication token and at least the second authentication token correspond to an identity associated with the user. The processing circuitry can validate a computing session responsive to determining that the first authentication token and at least the second authentication token can be linked to the identity. Other methods and systems are described.


