Indirect Authentication via Authorizing Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional password login methods for electronic display devices are insecure when used in public settings, as passwords can be seen and compromised by unauthorized bystanders, and shielding the screen is not a desirable retail strategy.

Innovation Solution

Implementing an indirect device authorization system where a display device operates in a display mode by default and can switch to an authorized mode via a separate authorizing device, allowing restricted content access through wireless authorization, using non-alphanumeric authentication schemes and gestures or visual cues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional password login interface is used for accessing restricted content on the display device, then the device can be secured against unauthorized access, but the security is compromised in public settings where passwords can be seen and made repeatable by unauthorized bystanders

Engineering Contradiction:
Improvesecurity of restricted contentVSAvoidpassword visibility to unauthorized bystanders
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that does not rely on visible passwords. Instead, the system uses a combination of device state changes and implicit user actions to authenticate users. The authentication process occurs in the background through state transitions and user interaction patterns, eliminating the need for visible password entry in public settings.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical/password-based authentication system with a state-based authentication mechanism. Rather than relying on visible text passwords, the system uses changes in device state, user interaction patterns, and implicit authentication to secure access. This substitution eliminates the vulnerability of visible passwords while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If the display device uses a secure authentication method that prevents password visibility, then security against bystanders is improved, but the ease of operation for employees accessing restricted content may be reduced

Engineering Contradiction:
Improvesecurity against password visibilityVSAvoidaccess method for employees
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system performs self-service authentication through automatic state changes and implicit user actions. When an employee needs to access restricted content, the system automatically detects their intent through their interaction pattern and initiates the appropriate state transition. This eliminates the need for employees to manually enter passwords or undergo complex authentication procedures, maintaining ease of operation while ensuring security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system prepares authentication states in advance and automatically transitions between them based on user interactions. Authentication credentials and access rights are pre-configured in the device state, allowing employees to access restricted content through simple, intuitive actions without needing to remember or enter complex passwords. The preliminary setup of authentication states enables seamless access while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If the display device is configured to allow unrestricted access to all content, then ease of operation for customers is improved, but security and proprietary information protection are compromised

Engineering Contradiction:
Improveaccessibility of contentVSAvoidprotection of restricted content
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The display device dynamically adjusts its content accessibility based on the current authentication state. The system transitions between different operational modes (e.g., customer view mode and employee access mode) based on user interactions and authentication status. This dynamic configuration allows unrestricted access to appropriate content for authenticated users while automatically restricting access to sensitive information for unauthenticated users, balancing ease of operation with security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different content accessibility rules to different parts of the system based on user authentication status. Authenticated users receive full access to both public and restricted content, while unauthenticated users receive limited access to public content only. This local differentiation of access rights ensures that ease of operation is maintained for authorized users while security is protected for restricted content.

Inventive Principle:
Principle #3Local quality

4Reliability

If the display device implements comprehensive access control for all content, then security of restricted information is improved, but the complexity of the device increases

Engineering Contradiction:
Improveaccess control for restricted contentVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication functions into a unified state-based system. Rather than implementing separate authentication mechanisms for different content types and user roles, the system uses a single coherent state management framework that handles all authentication needs. This consolidation reduces overall system complexity while maintaining comprehensive access control, as the unified state machine naturally accommodates different access scenarios without requiring separate complex subsystems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10484384B2Indirect authentication
Publication Date: 2019.11.19 APPLE INC
  • US10484384B2 patent drawing
  • US10484384B2 patent drawing
  • US10484384B2 patent drawing

AI summary

Techniques are provided for or granting authorization to restricted content on a display device from an authorizing device. In one embodiment, the display device may operate in a display mode where only unrestricted content is accessible. To access restricted content, the display device may transmit an authorization request signal to the authorizing device. The authorizing device, having received the authorization request, prompts an authorized user to enter an authentication input, such as a password or gesture, on the authorizing device. Upon verification of the authentication input, the authorizing device is authenticated. An authorization signal is transmitted to the display device, and the display device may operate in an authorized mode, having access to otherwise restricted content or functions.