Gateway Token Storage for Passwordless Cloud Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods using passwords for cloud-based services are cumbersome and insecure, leading to difficulties in managing multiple passwords, increased vulnerability to security threats, and unintended access by unauthorized users.

Innovation Solution

Implementing a gateway device that stores and manages authentication tokens within an on-premises network, allowing authorized devices to access cloud-based services without the need for passwords, thereby enhancing security and management efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional password-based authentication methods are used for cloud-based services, then users can access services across multiple devices, but security vulnerabilities increase and password management becomes cumbersome

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication credential storage function from individual devices and centralizes it in a gateway device. The gateway stores authentication tokens securely, while client devices only store references to these tokens. This separation removes passwords from vulnerable locations and centralizes security management, resolving the contradiction between security and ease of management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The gateway device acts as an intermediary between client devices and cloud services. It authenticates clients using stored tokens and mediates access requests to cloud services. This intermediary role eliminates the need for clients to directly handle passwords, improving both security (passwords never leave the gateway) and ease of operation (automatic authentication).

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple passwords are required for different applications, then access to various cloud services is enabled, but management complexity and security risks increase

Engineering Contradiction:
Improvemulti-service accessVSAvoidauthentication management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway device provides universal authentication functionality for multiple cloud services. Instead of requiring separate password management for each service, the gateway stores tokens for multiple services and handles authentication for all of them through a single interface. This multi-functional approach enables access to various services while simplifying management to a single centralized system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If passwords are stored on individual devices, then access convenience is improved, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts authentication credentials from client devices and relocates them to a dedicated gateway device. Client devices store only authentication references, not actual passwords. This extraction eliminates the security vulnerability of storing passwords on multiple potentially compromised devices while maintaining access convenience through automatic authentication via the gateway.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The gateway device provides self-service authentication to client devices. When a client needs to access a cloud service, it automatically obtains authentication tokens from the gateway without user intervention or password input. This self-service mechanism maintains access convenience while eliminating password handling on client devices, reducing security risks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12463963B2Centralized authentication storage and management for cloud-based services
Publication Date: 2025.11.04 VERIZON PATENT & LICENSING INC
  • US12463963B2 patent drawing
  • US12463963B2 patent drawing
  • US12463963B2 patent drawing

AI summary

Systems and methods for providing centralized authentication storage and management are described. An illustrative method includes a gateway device detecting that a first computing device connected to an on-premises network logs into a cloud-based service by way of the gateway device, stores an authentication token provided to the gateway device by the cloud-based service, and obtains authorization data indicating that a second computing device connected to the on-premises network is authorized to access the cloud-based service. The method may further include a gateway device that shares the authentication token with a second computing device.