Cross-Device User Authentication Using Image-Based Identity Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in determining whether users are the same user across multiple electronic devices, necessitating separate authentication operations, especially in hardware-linked systems.
Innovation Solution
A device management system that uses image capturing to track users moving between electronic devices, allowing authentication and operation linkage by confirming user identity based on captured images, enabling single sign-on across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication is performed separately at each electronic device, then security and reliability are maintained, but user convenience and operation efficiency deteriorate due to repeated authentication requirements
Solution Approach 1:
The system segments the authentication process into two parts: (1) biometric authentication at the first electronic device, and (2) automatic credential transmission to the second electronic device. This segmentation allows the first device to perform secure biometric verification while the second device receives pre-authenticated credentials, eliminating repeated authentication requirements while maintaining security through the biometric gatekeeping function.
Solution Approach 2:
The system performs preliminary authentication at the first electronic device before the user reaches the second device. The authentication information is obtained in advance through biometric verification, and the credential transmission is prepared beforehand, allowing the second device to skip the authentication step and proceed directly to service access.
2Adaptability or versatility
If separate authentication operations are required at each device, then device security is maintained, but system complexity and user burden increase
Solution Approach 1:
The system implements a universal authentication mechanism where a single biometric authentication at the first electronic device generates credentials that are valid across multiple electronic devices. The management server acts as a universal coordinator that issues tokens recognizable by various devices, allowing one authentication event to serve multiple devices and functions.
Solution Approach 2:
The management server serves as an intermediary between the first electronic device and the second electronic device. It receives authentication information from the first device, processes it through secure token generation, and transmits the resulting credentials to the second device. This intermediary role simplifies the overall system by centralizing the complex authentication logic in one location rather than requiring each device to implement full authentication capabilities.
3Productivity
If authentication information is transmitted between devices, then user convenience improves through single sign-on, but information security and transmission safety face challenges
Solution Approach 1:
Instead of transmitting the actual biometric authentication information or sensitive credentials, the system creates a secure copy in the form of a token or credential that represents the authenticated state. This token is transmitted to the second device, allowing authentication without exposing the original biometric data or sensitive information, thus maintaining security while enabling cross-device access.
Solution Approach 2:
The system transforms the authentication information through parameter changes during transmission. The original biometric data is converted into a different format (token/credential) with different security properties - the transformed parameter maintains the authentication validity while being safer for transmission and storage, as it cannot be reverse-engineered to reveal the original biometric information.
Data Source
AI summary
An information processing apparatus includes circuitry configured to receive from a first electronic device first information acquired from a first user, determine whether a second user is a same person as the first user, and transmit second information to a second electronic device based on the first information.


