Decentralized Single Sign-On Protocol for Unsynced Device Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on protocols are not suited for decentralized networks of unsynchronized information technology devices, such as personal area networks, where no device acts as a central authentication server and clocks are not synchronized, leading to cumbersome authentication and increased security risks.

Innovation Solution

A single sign-on protocol that uses a far-expiry time period for the initial device authentication, enabling subsequent devices for a shorter near-expiry time period, ensuring secure data access while minimizing vulnerability by requiring frequent re-authentication and periodic authentication checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized authentication servers and synchronized clocks are used, then authentication security is improved, but system complexity and deployment difficulty worsen in decentralized networks

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the centralized authentication server and synchronized clock requirements from traditional single sign-on protocols. By removing these centralizing elements, the system enables decentralized authentication where each device maintains its own clock and authentication state, eliminating the need for complex centralized infrastructure while preserving security through distributed trust mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication process is segmented into independent device-level operations rather than centralized processing. Each device independently manages its authentication state and time, dividing the authentication function across multiple nodes. This segmentation eliminates the single point of failure and reduces overall system complexity while maintaining security through distributed validation.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If long authentication time periods are used, then user convenience is improved, but security vulnerability increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic authentication time periods where the allowed access duration is not fixed but adapts based on device trust levels and security context. The authentication time window expands or contracts dynamically, providing longer access for trusted devices while maintaining shorter windows for less trusted ones, thus balancing convenience and security vulnerability reduction.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication parameter of time duration is made variable rather than static. The system changes the time parameter based on multiple factors including device reputation, network context, and security policies. This parameter change allows the system to extend authentication validity for convenient user access while simultaneously reducing vulnerability by limiting the window for potential attacks.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If frequent authentication checks are required, then security is improved, but operational burden increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of continuous or frequent manual authentication checks, the patent implements periodic authentication validation based on time windows and device trust states. The system performs authentication checks at specific periodic intervals rather than continuously, reducing operational burden while maintaining security through regular validation cycles that align with device clock synchronization.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication system performs self-validation using device-built-in clocks and trust mechanisms without requiring external authentication servers or manual intervention. Each device autonomously validates authentication status based on its local time and stored trust information, eliminating the need for frequent manual authentication checks while maintaining security through automated periodic validation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7620978B1Securely propagating authentication in an ensemble of devices using single sign-on
Publication Date: 2009.11.17 MICRO FOCUS LLC
  • US7620978B1 patent drawing
  • US7620978B1 patent drawing
  • US7620978B1 patent drawing

AI summary

A single sign-on technique suitable for a network of devices with no centralized device or synchronized clocks such as a personal area network (PAN) is described. Responsive to a user signing-on to a first device via its user interface, the first device securely propagates authentication of the user for enabling one or more other devices in the network, each for a near-expiry time period measured from the device specific time of the respective device; thus providing for expiration of authentication to minimize how long data is vulnerable in case a device is lost or stolen. Described also is a device enabling protocol using authentication accumulation to secure against threats from a rogue device pretending to be another device in the network such as in man-in-the-middle and replay attacks.