IoT Single Sign-In via Third-Party Authentication Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IoT devices face the challenge of requiring separate authentication credentials for IoT support services and third-party services, leading to complex authentication processes and management of device secrets.

Innovation Solution

Implementing a single sign-in mechanism where an IoT device, already authenticated with a third-party service, can automatically authenticate with the IoT support service based on trust in the third-party provider's authentication, eliminating the need for additional credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication credentials are used for IoT support services and third-party services, then authentication security is maintained, but authentication process complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication credentials (IoT support service credentials and third-party service credentials) into a single unified credential structure. The device secret now contains both the IoT support service client secret and the third-party service client secret, allowing the device to authenticate with both services using one authentication flow rather than requiring separate credential management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified device secret serves multiple authentication purposes simultaneously. It functions as both the IoT support service credential and the third-party service credential, enabling the device to access multiple services with a single authentication mechanism. This multi-functional credential eliminates the need for separate authentication processes while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication credentials are managed separately, then service security is ensured, but credential management complexity increases

Engineering Contradiction:
Improveservice securityVSAvoidcredential management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the management of multiple credentials into a single device secret structure. Instead of separately managing IoT support service credentials and third-party service credentials, both are integrated into one unified credential that the device holds and uses for authentication with both services.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The device automatically manages its own unified credentials through the provisioning process. The device secret is provisioned to the device in a single operation, and the device uses this self-contained credential for automatic authentication with both IoT support services and third-party services without requiring manual credential management or intervention.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional authentication methods are used for each service, then service-specific security is maintained, but authentication time increases

Engineering Contradiction:
Improveservice-specific securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary provisioning of the unified device secret during device setup, incorporating both IoT support service and third-party service credentials in advance. This preliminary action ensures that when the device needs to authenticate with either service, it already possesses the necessary credentials, eliminating the need for repeated authentication setup and reducing authentication time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12058519B2Single sign-in for IoT devices
Publication Date: 2024.08.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12058519B2 patent drawing
  • US12058519B2 patent drawing
  • US12058519B2 patent drawing

AI summary

In one example of the technology, a first third-party service is registered with the IoT support service. A first IoT device of a plurality of IoT devices is caused to be provisioned with the IoT support service. An authentication is received token for the first IoT device. The authentication token is based on an authentication of the first IoT device with the first third-party service. The authentication token is verified. The first IoT device is authenticated with the IoT support service based on the verification.