eSIM Resource Reservation for Secure Shared Workstation Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for accessing physical computing resources in shared environments are inefficient and vulnerable to security threats due to lack of device authentication and inefficient allocation, particularly in distributed workforces with varying schedules and needs.

Innovation Solution

Implementing an embedded subscriber identity module (eSIM) on computing devices to manage resource reservations through unique device profiles, ensuring secure and efficient access by authenticating devices and users via wireless network connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If freely available workstations are utilized without authentication, then accessibility and ease of operation are improved, but security vulnerabilities and resource allocation efficiency deteriorate

Engineering Contradiction:
Improveaccessibility to workstationsVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication of computing devices before granting access to physical computing resources. Device profiles are pre-configured with authentication credentials, and the reservation service pre-validates device authorization before allowing connection to workstations, printers, or other shared resources. This preliminary verification eliminates security vulnerabilities while maintaining ease of operation for authorized devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device authentication is implemented, then security and resource allocation efficiency are improved, but device complexity and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses embedded subscriber identity modules (eSIM) to store and manage device profile copies that contain authentication credentials. Instead of complex centralized authentication servers, each computing device holds a verified copy of its authentication profile, enabling self-authentication. This approach maintains high security while reducing system complexity by distributing authentication capabilities to individual devices.

Inventive Principle:
Principle #26Copying

3Ease of operation

If first-come-first-serve access is used, then ease of operation is improved, but resource allocation efficiency and user satisfaction deteriorate for distributed workforces

Engineering Contradiction:
Improveaccess method simplicityVSAvoidresource allocation efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The reservation service enables users to pre-book physical computing resources in advance by submitting reservation requests with desired time slots and resource types. The system pre-allocates resources to authorized devices based on these reservations, ensuring that distributed workforce members can secure needed workstations, printers, or meeting room equipment before arrival. This maintains operational simplicity while dramatically improving resource allocation efficiency and user satisfaction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12598462B2Reservations of computing resources
Publication Date: 2026.04.07 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US12598462B2 patent drawing
  • US12598462B2 patent drawing
  • US12598462B2 patent drawing

AI summary

An example computing device accesses a resource allocation network service utilizing a wireless network connection in accordance with embedded SIM (eSIM) functionality to identify and reserve computing resources. The computing device transmits a request to the resource allocation server that includes computing device profile information stored in the eSIM. The resource allocation network service processes the requests and receives additional profile information from the identified physical computing resource. The resource allocation network service then establishes a reservation and generates allocation information that includes credential information and is sent to the requesting computing device and the physical computing resource. When the computing device attempts to access the computing resource (e.g., the workstation), the physical computing resource authenticates the computing device based allocation information transmitted by the computing device.