Indirect Authentication via Authorizing Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional password login methods for electronic display devices are insecure when used in public settings, as passwords can be seen and compromised by unauthorized bystanders, and shielding the screen is not a desirable retail strategy.
Innovation Solution
Implementing an indirect device authorization system where a display device operates in a display mode by default and can switch to an authorized mode via a separate authorizing device, allowing restricted content access through wireless authorization, using non-alphanumeric authentication schemes and gestures or visual cues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional password login interface is used for accessing restricted content on the display device, then the device can be secured against unauthorized access, but the security is compromised in public settings where passwords can be seen and made repeatable by unauthorized bystanders
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that does not rely on visible passwords. Instead, the system uses a combination of device state changes and implicit user actions to authenticate users. The authentication process occurs in the background through state transitions and user interaction patterns, eliminating the need for visible password entry in public settings.
Solution Approach 2:
The patent replaces the traditional mechanical/password-based authentication system with a state-based authentication mechanism. Rather than relying on visible text passwords, the system uses changes in device state, user interaction patterns, and implicit authentication to secure access. This substitution eliminates the vulnerability of visible passwords while maintaining security.
2Reliability
If the display device uses a secure authentication method that prevents password visibility, then security against bystanders is improved, but the ease of operation for employees accessing restricted content may be reduced
Solution Approach 1:
The authentication system performs self-service authentication through automatic state changes and implicit user actions. When an employee needs to access restricted content, the system automatically detects their intent through their interaction pattern and initiates the appropriate state transition. This eliminates the need for employees to manually enter passwords or undergo complex authentication procedures, maintaining ease of operation while ensuring security.
Solution Approach 2:
The system prepares authentication states in advance and automatically transitions between them based on user interactions. Authentication credentials and access rights are pre-configured in the device state, allowing employees to access restricted content through simple, intuitive actions without needing to remember or enter complex passwords. The preliminary setup of authentication states enables seamless access while maintaining security.
3Ease of operation
If the display device is configured to allow unrestricted access to all content, then ease of operation for customers is improved, but security and proprietary information protection are compromised
Solution Approach 1:
The display device dynamically adjusts its content accessibility based on the current authentication state. The system transitions between different operational modes (e.g., customer view mode and employee access mode) based on user interactions and authentication status. This dynamic configuration allows unrestricted access to appropriate content for authenticated users while automatically restricting access to sensitive information for unauthenticated users, balancing ease of operation with security.
Solution Approach 2:
The patent applies different content accessibility rules to different parts of the system based on user authentication status. Authenticated users receive full access to both public and restricted content, while unauthenticated users receive limited access to public content only. This local differentiation of access rights ensures that ease of operation is maintained for authorized users while security is protected for restricted content.
4Reliability
If the display device implements comprehensive access control for all content, then security of restricted information is improved, but the complexity of the device increases
Solution Approach 1:
The patent merges multiple authentication functions into a unified state-based system. Rather than implementing separate authentication mechanisms for different content types and user roles, the system uses a single coherent state management framework that handles all authentication needs. This consolidation reduces overall system complexity while maintaining comprehensive access control, as the unified state machine naturally accommodates different access scenarios without requiring separate complex subsystems.
Data Source
AI summary
Techniques are provided for or granting authorization to restricted content on a display device from an authorizing device. In one embodiment, the display device may operate in a display mode where only unrestricted content is accessible. To access restricted content, the display device may transmit an authorization request signal to the authorizing device. The authorizing device, having received the authorization request, prompts an authorized user to enter an authentication input, such as a password or gesture, on the authorizing device. Upon verification of the authentication input, the authorizing device is authenticated. An authorization signal is transmitted to the display device, and the display device may operate in an authorized mode, having access to otherwise restricted content or functions.


