Invitation Code Authentication for Secure Multi-Device Account Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-user software systems face challenges in providing secure and convenient account access, particularly when users need to authenticate multiple devices or invite new users, as current methods require knowledge of device identifiers or burdensome administrator verification.

Innovation Solution

A system that allows users to generate and share unique invitation codes for account access, eliminating the need for device knowledge and simplifying the authentication process by using application-specific identifiers and secure communication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional username and password authentication is used for each account, then security is maintained, but user convenience deteriorates due to the burden of remembering multiple credentials

Engineering Contradiction:
Improveaccount securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an invitation code as an intermediary authentication mechanism between the user and the account system. Instead of directly using username and password, the user generates an invitation code that serves as a temporary credential for inviting others to join the account, thereby reducing the need for users to manually manage multiple passwords while maintaining security through controlled access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device identifiers are required for invitation processes, then account security is improved, but device complexity increases as users must locate and share specific device information

Engineering Contradiction:
Improveaccount securityVSAvoidinvitation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication element (invitation code) from the complex device identifier information and uses only what is necessary for the invitation process. The system generates a simplified invitation code that contains the necessary authentication data without requiring users to handle or share complete device identifiers, thereby reducing complexity while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms the authentication parameter from complex device identifiers to simplified invitation codes. This parameter change allows the system to maintain security requirements while presenting a much simpler interface to users, eliminating the need for them to locate, copy, or share detailed device information

Inventive Principle:
Principle #35Parameter changes

3Reliability

If administrator verification is required for user invitations, then unauthorized access is prevented, but productivity decreases due to the time-consuming verification process

Engineering Contradiction:
Improveaccess controlVSAvoiduser invitation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by having the account holder pre-generate invitation codes with embedded authentication information before the actual invitation occurs. This preliminary preparation of credentials allows for automated verification without requiring real-time administrator intervention, thus maintaining access control while significantly improving invitation efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service authentication through invitation codes that contain all necessary verification information. The system can automatically verify the authenticity of invitation codes without requiring administrator intervention, allowing users to invite others independently while maintaining security through automated validation mechanisms

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230244776A1Secure association of an installed application instance with a service
Publication Date: 2023.08.03 BITSTRATA SYST INC
  • US20230244776A1 patent drawing
  • US20230244776A1 patent drawing
  • US20230244776A1 patent drawing

AI summary

The disclosed embodiments relate to systems and methods for securely associating an application installation with an account of a service. The computer implemented method may include an inviting device with authenticated access to an account provided by a service having data stored therein. An invite code may be generated in response to a request to enable another device to have access to the service account without identifying the other device. The inviting device may provide the invite code to an invited device. The disclosed embodiments enable an inviting device to provide secure and convenient authenticated account access to multiple devices.