Gateway Token Storage for Passwordless Cloud Service Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods using passwords for cloud-based services are cumbersome and insecure, leading to difficulties in managing multiple passwords, increased vulnerability to security threats, and unintended access by unauthorized users.
Innovation Solution
Implementing a gateway device that stores and manages authentication tokens within an on-premises network, allowing authorized devices to access cloud-based services without the need for passwords, thereby enhancing security and management efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional password-based authentication methods are used for cloud-based services, then users can access services across multiple devices, but security vulnerabilities increase and password management becomes cumbersome
Solution Approach 1:
The patent extracts the authentication credential storage function from individual devices and centralizes it in a gateway device. The gateway stores authentication tokens securely, while client devices only store references to these tokens. This separation removes passwords from vulnerable locations and centralizes security management, resolving the contradiction between security and ease of management.
Solution Approach 2:
The gateway device acts as an intermediary between client devices and cloud services. It authenticates clients using stored tokens and mediates access requests to cloud services. This intermediary role eliminates the need for clients to directly handle passwords, improving both security (passwords never leave the gateway) and ease of operation (automatic authentication).
2Adaptability or versatility
If multiple passwords are required for different applications, then access to various cloud services is enabled, but management complexity and security risks increase
Solution Approach 1:
The gateway device provides universal authentication functionality for multiple cloud services. Instead of requiring separate password management for each service, the gateway stores tokens for multiple services and handles authentication for all of them through a single interface. This multi-functional approach enables access to various services while simplifying management to a single centralized system.
3Ease of operation
If passwords are stored on individual devices, then access convenience is improved, but security vulnerabilities and unauthorized access risks increase
Solution Approach 1:
The patent extracts authentication credentials from client devices and relocates them to a dedicated gateway device. Client devices store only authentication references, not actual passwords. This extraction eliminates the security vulnerability of storing passwords on multiple potentially compromised devices while maintaining access convenience through automatic authentication via the gateway.
Solution Approach 2:
The gateway device provides self-service authentication to client devices. When a client needs to access a cloud service, it automatically obtains authentication tokens from the gateway without user intervention or password input. This self-service mechanism maintains access convenience while eliminating password handling on client devices, reducing security risks.
Data Source
AI summary
Systems and methods for providing centralized authentication storage and management are described. An illustrative method includes a gateway device detecting that a first computing device connected to an on-premises network logs into a cloud-based service by way of the gateway device, stores an authentication token provided to the gateway device by the cloud-based service, and obtains authorization data indicating that a second computing device connected to the on-premises network is authorized to access the cloud-based service. The method may further include a gateway device that shares the authentication token with a second computing device.


