Multi-device network sign-on via access perimeter authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer networks require users to authenticate multiple devices separately, increasing user burden and potentially compromising network security when allowing device access without authentication.

Innovation Solution

Implementing a multi-device single network sign-on method that authenticates a primary device and allows secondary devices within a configurable access perimeter to access the network without additional authentication, using distance or network access points as criteria for access permission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional networks require separate authentication for each device, then network security is maintained, but user burden increases and ease of operation deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication process complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent combines multiple device authentications into a single authentication process. When a user authenticates on one device (primary device), the system merges this authentication state across multiple devices, allowing them to access the network without separate authentication processes. This is achieved through the access perimeter concept that tracks authenticated users and their authorized devices collectively.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed with multi-functionality to serve multiple devices simultaneously. The single authentication process performs the function of authenticating not just one device but multiple devices within the access perimeter, making the authentication mechanism universal rather than device-specific.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If multi-device single network sign-on is implemented, then user convenience is improved, but network security risks increase

Engineering Contradiction:
Improveease of accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by creating a localized access perimeter around each authenticated user. Instead of providing universal access to all devices, the system establishes a specific perimeter (geographic, network-based, or a combination) that is unique to each user's authentication session. Devices must be physically or logically within this perimeter to access the network, ensuring that convenience is granted only in appropriate local contexts.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The access perimeter is dynamic rather than static. It changes based on the authenticated user's location, network connectivity status, and other real-time conditions. The perimeter can expand or contract, move, or reconfigure as the user moves between locations or network conditions change, maintaining security adaptability while preserving ease of access within the defined perimeter.

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If access perimeter is defined by distance only, then implementation is simple, but security control precision deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidaccess control precision
Core Design Contradiction:
Ease of manufactureVSManufacturing precision

Solution Approach 1:

The patent segments the access perimeter definition into multiple independent criteria that can be combined or used separately. The perimeter can be defined by distance alone for simplicity, or by network access points alone, or by a combination of both distance and network-based criteria. This segmentation allows flexible configuration where implementation complexity can be adjusted based on specific security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system allows changing the parameters used to define the access perimeter based on operational needs. Administrators can switch between distance-based parameters, network access point-based parameters, or composite parameters. This parameter flexibility enables the system to adapt between simple implementation modes and high-precision security control modes as required.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10044709B2Multi-device single network sign-on
Publication Date: 2018.08.07 EXTREME NETWORKS INC
  • US10044709B2 patent drawing
  • US10044709B2 patent drawing
  • US10044709B2 patent drawing

AI summary

Methods, systems and computer readable media for multi-device single network sign-on are described. For example, a method can include authenticating a first device for network access via a first authentication process, the first device being associated with a user account. The method can also include receiving an access request from a second device associated with the user account, and determining whether the second device is within an access perimeter of the first device. The method can further include permitting the second device to access the network without a second authentication process when the second device is within the access perimeter of the first device.