Device Token Protocol for Unified Application Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication and authorization techniques are cumbersome and insecure, particularly for multiple applications from the same vendor, as they require separate user authentication and storage of credentials on each device, lacking centralized management and persistent, non-transferable tokens for secure access across applications.

Innovation Solution

A device token protocol that provides persistent, non-transferable authentication across applications by using a device token uniquely associated with both the device and user, managed centrally to enhance security and remote management capabilities, eliminating the need for local credential storage and enabling unified authorization and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate user authentication and credential storage is implemented for each application, then each application can be authenticated independently, but the process becomes cumbersome and security is compromised

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines authentication across multiple applications into a single unified process. Instead of requiring separate authentication for each application, the system uses a single authentication token that provides access to multiple applications, thereby simplifying the user experience while maintaining security through centralized credential management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication token serves multiple functions across different applications. A single token obtained from one application can be used to access other applications, making the authentication mechanism universal rather than application-specific, thus eliminating the need for repeated authentication processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If credentials are stored locally on each device, then access can be granted, but credential exposure and security risks increase

Engineering Contradiction:
Improveaccess capabilityVSAvoidcredential exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication token system that mediates between the user's credentials and application access. Instead of storing sensitive credentials locally on devices, the system uses this intermediary token mechanism to verify identity and grant access, thereby reducing the security risks associated with local credential storage while maintaining access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If centralized management is implemented, then security and remote management capabilities are enhanced, but system complexity increases

Engineering Contradiction:
Improveremote management capabilityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex credential storage and management functionality from individual applications and devices, concentrating it in a centralized system. This extraction allows the centralized system to handle security and management tasks, providing remote management capabilities while keeping individual applications and devices simpler in structure.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If persistent authentication tokens are used, then re-authentication is eliminated, but token management and revocation become more complex

Engineering Contradiction:
Improveauthentication convenienceVSAvoidtoken management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms in the centralized system that enable token revocation and management. When a user needs to revoke access or when security concerns arise, the centralized system can feedback to remove or invalidate tokens, allowing persistent authentication convenience while providing necessary control and management capabilities through centralized feedback loops.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9038138B2Device token protocol for authorization and persistent authentication shared across applications
Publication Date: 2015.05.19 ADOBE INC
  • US9038138B2 patent drawing
  • US9038138B2 patent drawing
  • US9038138B2 patent drawing

AI summary

Various techniques for providing a device token protocol for authorization and persistent authentication shared across applications are disclosed. In some embodiments, a device token protocol for authorization and persistent authentication shared across applications includes sending user credentials to a remote server to authenticate a user on a device for a plurality of applications; and receiving a device token from the remote server for the user to authenticate the user for the plurality of applications on the device, in which the device token facilitates authentication and authorization.