Decentralized Single Sign-On Protocol for Unsynced Device Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on protocols are not suited for decentralized networks of unsynchronized information technology devices, such as personal area networks, where no device acts as a central authentication server and clocks are not synchronized, leading to cumbersome authentication and increased security risks.
Innovation Solution
A single sign-on protocol that uses a far-expiry time period for the initial device authentication, enabling subsequent devices for a shorter near-expiry time period, ensuring secure data access while minimizing vulnerability by requiring frequent re-authentication and periodic authentication checks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized authentication servers and synchronized clocks are used, then authentication security is improved, but system complexity and deployment difficulty worsen in decentralized networks
Solution Approach 1:
The patent extracts the centralized authentication server and synchronized clock requirements from traditional single sign-on protocols. By removing these centralizing elements, the system enables decentralized authentication where each device maintains its own clock and authentication state, eliminating the need for complex centralized infrastructure while preserving security through distributed trust mechanisms.
Solution Approach 2:
The authentication process is segmented into independent device-level operations rather than centralized processing. Each device independently manages its authentication state and time, dividing the authentication function across multiple nodes. This segmentation eliminates the single point of failure and reduces overall system complexity while maintaining security through distributed validation.
2Ease of operation
If long authentication time periods are used, then user convenience is improved, but security vulnerability increases
Solution Approach 1:
The patent implements dynamic authentication time periods where the allowed access duration is not fixed but adapts based on device trust levels and security context. The authentication time window expands or contracts dynamically, providing longer access for trusted devices while maintaining shorter windows for less trusted ones, thus balancing convenience and security vulnerability reduction.
Solution Approach 2:
The authentication parameter of time duration is made variable rather than static. The system changes the time parameter based on multiple factors including device reputation, network context, and security policies. This parameter change allows the system to extend authentication validity for convenient user access while simultaneously reducing vulnerability by limiting the window for potential attacks.
3Reliability
If frequent authentication checks are required, then security is improved, but operational burden increases
Solution Approach 1:
Instead of continuous or frequent manual authentication checks, the patent implements periodic authentication validation based on time windows and device trust states. The system performs authentication checks at specific periodic intervals rather than continuously, reducing operational burden while maintaining security through regular validation cycles that align with device clock synchronization.
Solution Approach 2:
The authentication system performs self-validation using device-built-in clocks and trust mechanisms without requiring external authentication servers or manual intervention. Each device autonomously validates authentication status based on its local time and stored trust information, eliminating the need for frequent manual authentication checks while maintaining security through automated periodic validation.
Data Source
AI summary
A single sign-on technique suitable for a network of devices with no centralized device or synchronized clocks such as a personal area network (PAN) is described. Responsive to a user signing-on to a first device via its user interface, the first device securely propagates authentication of the user for enabling one or more other devices in the network, each for a near-expiry time period measured from the device specific time of the respective device; thus providing for expiration of authentication to minimize how long data is vulnerable in case a device is lost or stolen. Described also is a device enabling protocol using authentication accumulation to secure against threats from a rogue device pretending to be another device in the network such as in man-in-the-middle and replay attacks.


