Multi-Tenant Credential Segmentation for Secure Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack an automated mechanism to securely identify and associate computing devices in un-trusted environments, relying on unsecured methods like email for authentication, which fails to verify the origin and integrity of communications.
Innovation Solution
A computing device generates and transmits a unique credential to another device, allowing secure communication and service exposure based on this credential, enabling multi-tenant access and authentication without human intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If unsecured electronic mail is used for authentication, then ease of operation is improved, but reliability of authentication is worsened
Solution Approach 1:
The authentication system segments the credential into two parts: a shared first credential (common to multiple devices) and a device-specific second credential. This segmentation allows automated secure authentication while maintaining ease of operation through programmatic credential exchange without manual intervention.
Solution Approach 2:
The patent introduces a credential intermediary mechanism where a first computing device acts as an intermediary to issue device-specific credentials to second computing devices. This intermediary layer provides automated verification and credential distribution, improving both reliability and ease of operation compared to unsecured email authentication.
2Reliability
If automated credential-based authentication is implemented, then reliability of authentication is improved, but device complexity is worsened
Solution Approach 1:
The first computing device serves multiple functions: it acts as a credential issuer, a verification authority, and a service gateway. This universal device reduces overall system complexity by consolidating authentication functions in a single device rather than requiring complex distributed authentication infrastructure.
Solution Approach 2:
The first computing device performs preliminary actions by pre-issuing device-specific credentials to second computing devices before actual service access is needed. This preliminary credential distribution simplifies subsequent authentication processes and reduces the complexity of real-time verification mechanisms.
3Measurement precision
If device-specific credentials are generated and distributed, then measurement precision of device identification is improved, but loss of time in credential distribution is worsened
Solution Approach 1:
Device-specific credentials are generated and distributed in advance through automated processes before service access is required. This preliminary credential distribution eliminates time delays during actual authentication and achieves precise device identification without time loss during operational access.
Solution Approach 2:
The credential distribution system operates autonomously with automated credential generation, transmission, and verification processes. Second computing devices receive their credentials through self-service automated mechanisms without requiring manual intervention, thereby achieving precise device identification with minimal time loss.
Data Source
AI summary
Associating a computing device with a group of other computing devices. A service receives a common credential from the computing device and associates the computing device with the other computing devices also associated with the common credential. The service generates a machine-specific credential for use by the computing device in subsequent communications with the service. The machine-specific credential is used to authenticate, identify, and group the computing device with the other computing devices in the subsequent communications.


