Mobile Device Authentication Paths for Secure Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices, such as smartphones, are less shared due to concerns about exposing personal data, despite their convenience and multipurpose nature.
Innovation Solution
Implementing user authentication methods, including touch and touchless authentication, to determine user identity and provide access control, allowing device owners full access while offering pass-through access to guests or personal clouds for unauthorized users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user authentication and access control mechanisms are implemented to protect personal data, then data security is improved, but device sharing convenience deteriorates
Solution Approach 1:
The patent segments device access into multiple independent paths: a first device path for authenticated users with full access to device content and cloud data, and a second device path for unauthenticated users with limited access only to cloud storage. This segmentation allows different security levels for different user types, maintaining data security while enabling convenient sharing for unauthenticated users.
Solution Approach 2:
The patent applies local quality by providing different access permissions to different users based on their authentication status. Device owners and authenticated users receive full access permissions, while unauthenticated users receive restricted permissions limited to cloud storage only. This localized differentiation of access rights resolves the contradiction by tailoring security measures to specific user contexts.
2Adaptability or versatility
If multiple device paths are implemented to allow both authenticated and unauthenticated access, then device sharing capability is improved, but system complexity increases
Solution Approach 1:
The system is divided into distinct device paths with clearly defined access rules. The first device path handles authenticated users with full access, while the second device path handles unauthenticated users with cloud-only access. This segmentation makes the complexity manageable by creating modular, independent access control mechanisms rather than a monolithic system.
Solution Approach 2:
The patent introduces cloud storage as an intermediary that bridges authenticated and unauthenticated access. Unauthenticated users can access cloud storage without device authentication, while authenticated users access both device content and cloud storage. This intermediary approach enables versatile sharing without requiring complex permission management for every user type.
3Reliability
If unauthenticated users are restricted to cloud storage only, then personal data protection is improved, but user accessibility deteriorates
Solution Approach 1:
Cloud storage serves as an intermediary that provides unauthenticated users with useful access to their own cloud data without exposing device owner's personal data. This intermediary approach maintains personal data protection while still providing accessibility benefits to unauthenticated users, resolving the contradiction between security and usability.
Solution Approach 2:
Unauthenticated users can access their own cloud storage data without requiring device owner authentication or intervention. The system enables self-service access where users can manage and access their own cloud data independently, improving accessibility while maintaining data protection through user-specific access controls.
Data Source
AI summary
Systems and methods for providing multiple paths through a mobile electronic device entail providing one of multiple levels of device access and cloud access based on an identity determination and authentication as to a potential user. In an embodiment, the device attempts to identify the user based on traditional touch/touchless authentication techniques. If this attempt is unsuccessful, the device then tries to identify the user by alternative means. If the user can be identified, the device attempts to authenticate the user for full access to the device and associated cloud data. If this is successful, the user is granted full access. If instead the identified user is not qualified for full access, the user is given pass-through access to their personal cloud storage. If, however, the device is unable to even identify the user, the user may be given pass-through access to the cloud generally.


