Multi-Tenant Credential Segmentation for Secure Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack an automated mechanism to securely identify and associate computing devices in un-trusted environments, relying on unsecured methods like email for authentication, which fails to verify the origin and integrity of communications.

Innovation Solution

A computing device generates and transmits a unique credential to another device, allowing secure communication and service exposure based on this credential, enabling multi-tenant access and authentication without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unsecured electronic mail is used for authentication, then ease of operation is improved, but reliability of authentication is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system segments the credential into two parts: a shared first credential (common to multiple devices) and a device-specific second credential. This segmentation allows automated secure authentication while maintaining ease of operation through programmatic credential exchange without manual intervention.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a credential intermediary mechanism where a first computing device acts as an intermediary to issue device-specific credentials to second computing devices. This intermediary layer provides automated verification and credential distribution, improving both reliability and ease of operation compared to unsecured email authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If automated credential-based authentication is implemented, then reliability of authentication is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The first computing device serves multiple functions: it acts as a credential issuer, a verification authority, and a service gateway. This universal device reduces overall system complexity by consolidating authentication functions in a single device rather than requiring complex distributed authentication infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The first computing device performs preliminary actions by pre-issuing device-specific credentials to second computing devices before actual service access is needed. This preliminary credential distribution simplifies subsequent authentication processes and reduces the complexity of real-time verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If device-specific credentials are generated and distributed, then measurement precision of device identification is improved, but loss of time in credential distribution is worsened

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidcredential distribution time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Device-specific credentials are generated and distributed in advance through automated processes before service access is required. This preliminary credential distribution eliminates time delays during actual authentication and achieves precise device identification without time loss during operational access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The credential distribution system operates autonomously with automated credential generation, transmission, and verification processes. Second computing devices receive their credentials through self-service automated mechanisms without requiring manual intervention, thereby achieving precise device identification with minimal time loss.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8201231B2Authenticated credential-based multi-tenant access to a service
Publication Date: 2012.06.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8201231B2 patent drawing
  • US8201231B2 patent drawing
  • US8201231B2 patent drawing

AI summary

Associating a computing device with a group of other computing devices. A service receives a common credential from the computing device and associates the computing device with the other computing devices also associated with the common credential. The service generates a machine-specific credential for use by the computing device in subsequent communications with the service. The machine-specific credential is used to authenticate, identify, and group the computing device with the other computing devices in the subsequent communications.