Digital Badge Access for Managed Multi-User Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device management systems require frequent user authentication, which is cumbersome for IT employees accessing multiple devices daily, and shared devices necessitate repeated credential entry, slowing access.
Innovation Solution
A digital badge system allows secure access to multi-user devices using a single-user device without manual credentials, leveraging wireless communication protocols to authenticate and authorize access through a UEM system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users authenticate manually on each device, then security is maintained, but access time and user convenience deteriorate
Solution Approach 1:
The system performs preliminary authentication by obtaining user credentials before the user actually needs to access the device. The credential provider application pre-requests and stores authentication credentials, so when the user approaches a device, the authentication has already been prepared and can be automatically applied, eliminating the need for manual authentication at the moment of access.
Solution Approach 2:
The patent introduces a credential provider application and credential consumer application as intermediaries between the user and the device authentication system. These applications act as mediators that automatically handle the authentication process, transferring credentials from the user's device to the target device without requiring direct user interaction with the authentication interface, thus resolving the contradiction between security and access speed.
2Adaptability or versatility
If users authenticate on multiple devices, then access to multiple devices is enabled, but user convenience and operational simplicity deteriorate
Solution Approach 1:
The credential provider application is designed with multi-functionality to handle authentication across multiple different devices and applications. A single credential provider can supply credentials to various credential consumers on different devices, making the authentication system universal. This allows users to access multiple devices without needing separate authentication processes for each, thereby improving ease of operation while maintaining versatile device access capability.
3Reliability
If reauthentication is required at set time intervals, then security is enhanced, but user productivity and access efficiency deteriorate
Solution Approach 1:
The system establishes continuous authentication by implementing persistent credential validation across multiple applications and devices. Instead of requiring periodic reauthentication that interrupts user workflow, the credential provider maintains continuous valid credentials that are automatically refreshed and renewed in the background. This allows the authentication process to continue seamlessly without requiring user intervention at set time intervals, thus maintaining security while preserving productivity.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables seamless, secure access to multi-user devices by eliminating the need for repeated user authentication, enhancing efficiency and security by maintaining authorized access based on digital badge verification.
Implementation Method 1
The multi-user device can enable one or more wireless communication protocols, such as BLUETOOTH, BLUETOOTH LOW ENEGERGY ("BLE"), Near-Field Communication ("NFC"), or ultra-wide band ("UWB"). The multi-user device can send a broadcast on the wireless communication protocol that can be detected by the single-user device.
Data Source
AI summary
Systems and methods are described for accessing a first user device using a digital badge from a second user device. The digital badge can include information that can be used to identify and authenticate a user profile. In an example, the first and second user devices can be enrolled in a system for managing user devices. A user can select to login to the first user device using a digital badge. The first user device can enable a wireless communication protocol and broadcast a digital badge request that is recognizable by other enrolled devices. The second user device can detect the broadcast and send its digital badge to the first user device. The first user device can send an access request and the digital badge to a server. The server can verify the digital badge, authenticate the user, and notify the first user device. The first user device can then grant the user access without the user inputting any credentials.


