Unified User Identity Mapping for Cross-Platform Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the challenge of managing multiple device identities across devices with different operating systems, requiring separate authentication and login information, which complicates cross-device access and communication.

Innovation Solution

A system that maps multiple device identities to a single unified primary identity, using a centralized identity exchange service to validate and convert tokens such as OAuth and SAML, enabling seamless access across devices with different platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication is used for each device, then device security is maintained, but user operation complexity increases and cross-device access becomes difficult

Engineering Contradiction:
Improvedevice securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a key distribution server as an intermediary between devices and users. This server stores multiple device keys and mediates the authentication process by providing appropriate keys to devices based on user identity, thereby maintaining device security while simplifying user authentication across devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal authentication mechanism where a single user identity can access multiple devices through the key distribution server. The server provides multi-functional key management that works across different device types and platforms, eliminating the need for separate authentication procedures

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple device identities are maintained, then device individuality is preserved, but information management complexity increases

Engineering Contradiction:
Improvedevice individualityVSAvoididentity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key distribution server acts as an intermediary that manages the relationships between multiple device identities and user identities. It handles the complexity of tracking which keys belong to which devices and users, thereby preserving device individuality while relieving users of identity management complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates cryptographic key copies that represent device identities without requiring users to directly manage the complex identity structures. The key distribution server maintains the master identity records while distributing simplified key representations to devices and users

Inventive Principle:
Principle #26Copying

3Reliability

If platform-specific authentication is used, then platform security is maintained, but cross-platform communication becomes difficult

Engineering Contradiction:
Improveplatform securityVSAvoidcross-platform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key distribution server implements a universal key management system that works across different platforms and devices. It provides platform-agnostic authentication by translating between different device-specific key formats and a unified user identity model, thereby maintaining platform security while enabling cross-platform communication

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12537815B2Authorization of multiple user identities
Publication Date: 2026.01.27 LENOVO (SINGAPORE) PTE LTD
  • US12537815B2 patent drawing
  • US12537815B2 patent drawing
  • US12537815B2 patent drawing

AI summary

An apparatus can include an interface for receiving validation requests of a user. The apparatus can include processing circuitry coupled to the interface. The processing circuitry can receive a first validation request, the first validation request including a first virtual identity. The processing circuitry can provide, over the interface, a primary token responsive to validating the first virtual identity. The processing circuitry can provide the primary token upon validating that the subsequent validation requests correspond to the user responsive to receiving subsequent validation requests.