Mobile Device SSO Collaboration via Identity Token Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current single sign-on (SSO) technologies do not support seamless authentication across multiple mobile devices, requiring users to re-enter identity information each time they switch devices, which is inconvenient and increases administrative overhead.

Innovation Solution

A system and method for SSO collaboration among multiple mobile devices, where a server issues an identity token to authenticate a user on a first device and generates a collaboration key, allowing the user to securely access services on other paired devices without additional login procedures, using collaboration credentials and identity tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users log in to each mobile device separately with identity information, then security authentication is performed on each device, but users must re-enter credentials frequently and administrative overhead increases

Engineering Contradiction:
Improvesecurity authenticationVSAvoidlogin time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the authentication process by separating device-specific authentication from user identity authentication. Each mobile device receives a unique identity token that contains user identification information, allowing the device to authenticate independently without requiring repeated user credential entry. This segmentation enables automatic authentication across multiple devices while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The server performs preliminary authentication and issues identity tokens to multiple mobile devices before the user needs to access services. The identity tokens are pre-configured with user identification information, so when the user switches between devices, authentication has already been performed in advance, eliminating the need for repeated login procedures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If users log in to each mobile device separately with identity information, then device-specific authentication is ensured, but administrative overhead in resetting forgotten credentials increases

Engineering Contradiction:
Improveauthentication securityVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identity token serves multiple functions across different mobile devices. A single identity token issued by the server can be used by multiple registered devices to authenticate the same user account. This universality eliminates the need for device-specific credential management and reduces administrative overhead for resetting forgotten passwords, as the server can reissue identity tokens without requiring users to remember multiple passwords.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If users enter identity information on each device, then proper authentication is achieved, but user convenience and password management become difficult

Engineering Contradiction:
ImproveauthenticationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system creates digital copies of user identity information in the form of identity tokens that are distributed to multiple mobile devices. Instead of requiring users to manually enter their actual credentials on each device, the server issues copied identity representations (identity tokens) that contain the necessary authentication information. These tokens can be automatically presented by any registered device, greatly improving user convenience while maintaining authentication security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8955081B2Method and apparatus for single sign-on collaboraton among mobile devices
Publication Date: 2015.02.10 MOTOROLA SOLUTIONS INC
  • US8955081B2 patent drawing
  • US8955081B2 patent drawing
  • US8955081B2 patent drawing

AI summary

An apparatus for, and method of, single sign-on collaboration among a plurality of mobile devices, includes a server for issuing a first identity token to subsequently authenticate a user of a first of the mobile devices to a service provider, and for generating and sending a collaboration key to the first device based on the first identity token or user authentication. The first device generates and sends a collaboration credential based on the collaboration key to a second device paired with the first device. The server also issues a second identity token to subsequently authenticate to the service provider the user of the second device based on the collaboration credential received from the first device, to support single sign-on collaboration for the user across the plurality of mobile devices.