Global User ID for Multilevel Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Global entities face inefficiencies and security risks due to the need for multiple login credentials for each location, leading to increased login attempts and credential management burdens.

Innovation Solution

A system that allows a global user identification linked to multiple locations, enabling users to switch between experience environments without providing additional login credentials, by generating tailored graphical user interfaces based on selected experiences, which include access to relevant applications, currencies, and languages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate login credentials are required for each location, then access control to specific locations is improved, but user operation complexity and login time increase

Engineering Contradiction:
Improveaccess controlVSAvoidlogin time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple location-specific credentials into a single global credential system. Users authenticate once with a global username and password, then access multiple locations through a unified interface that dynamically presents location-specific data based on the user's role and permissions, eliminating the need for separate logins while maintaining access control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The global credential system serves multiple functions: it authenticates users, manages permissions across locations, and dynamically adapts the interface based on the selected location. This universal credential replaces multiple location-specific credentials while maintaining the ability to control access to each location appropriately.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate login credentials are required for each location, then location-specific security is improved, but system complexity increases

Engineering Contradiction:
Improvelocation-specific securityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple credential management functions into a single centralized authentication mechanism. Instead of managing separate credentials for each location, the system uses one global credential set that automatically manages access rights across all locations through server-side permission checks and dynamic interface generation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary authentication server that mediates between the user's global credentials and location-specific access requirements. This intermediary handles the complexity of credential verification and permission management, presenting a simplified interface to users while maintaining robust security controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If users must logout and login for each location, then access isolation between locations is improved, but productivity decreases

Engineering Contradiction:
Improveaccess isolationVSAvoiddata access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system combines access to multiple locations into a single continuous session. Users remain logged in while switching between locations through a unified interface that presents location-specific data and functionality based on the selected location, maintaining access isolation through server-side controls rather than requiring separate login sessions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system dynamically adapts the user interface and available functionality based on the selected location while maintaining a single authenticated session. The interface automatically adjusts to present relevant applications, data formats, and controls appropriate for each location, enabling seamless transitions without breaking the authentication context.

Inventive Principle:
Principle #15Dynamics

4Ease of operation

If multiple credentials are shared among users, then access to location information is improved, but security risks increase

Engineering Contradiction:
Improveaccess to location informationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system consolidates multiple shared credentials into individualized global credentials for each user. Each user has their own authenticated session with specific permissions, eliminating the security risks of shared credentials while maintaining ease of access to location information through the unified interface.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system segments access rights by assigning specific permissions to each user's global credential based on their role and needs. Instead of sharing a single credential, each user receives customized access rights that are enforced by the system, providing both security and appropriate access to location information.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10742635B2Multilevel sign-on
Publication Date: 2020.08.11 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US10742635B2 patent drawing
  • US10742635B2 patent drawing
  • US10742635B2 patent drawing

AI summary

A global userID may be linked to many individual locations. A user may login to the global userID and select an experience environment. The experience environment may provide access to locations associated with the experience environment, such as all locations in a country. The user may switch between experience environments without providing login credentials for each individual location the user wishes to view.