Multi-User Sign-On Management in Segmented Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing personal computing devices on networks lack effective multi-user management capabilities, particularly in segmented networks, leading to difficulties in providing secure and user-specific access to applications and data.

Innovation Solution

A personal device container system that includes a processor, memory, and executable code, which authenticates users, creates network tunnels, filters messages, and manages access to secured network segments based on security credentials and geographic location, allowing multiple users to access specific content and applications securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a segmented network structure is implemented to provide secure access to multiple applications, then network security is improved, but system complexity increases and multi-user management becomes difficult

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is divided into multiple segmented network segments, each providing secure access to specific applications or data. The system creates separate network tunnels for different applications, allowing isolated secure communication channels while maintaining overall network security architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system provides universal user profile management that works across multiple applications and network segments. A single user profile can be associated with multiple device identifiers and accessed across different applications, eliminating the need for separate authentication mechanisms for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication is required for each application, then security is improved, but user convenience deteriorates and access time increases

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system creates a universal user profile that can be associated with multiple device identifiers and used across different applications. Once authenticated, the user profile enables access to multiple applications without requiring re-authentication, providing both security and convenience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary authentication by creating and storing user profiles associated with device identifiers before application-specific access is needed. This preliminary action allows subsequent applications to quickly verify user identity without requiring full authentication again.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If user-specific information is stored for each application, then user customization is improved, but data management complexity and storage requirements increase

Engineering Contradiction:
Improveuser customizationVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal user profile structure that can store user-specific information and be associated with multiple device identifiers and applications. This single profile serves multiple applications, reducing data management complexity while maintaining user customization capabilities across all applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges user-specific information from multiple applications into a single unified user profile. Instead of maintaining separate data structures for each application, the profile consolidates user information, preferences, and credentials, simplifying data management while preserving application-specific customization.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If multiple device identifiers are associated with a single user, then multi-device support is improved, but authentication complexity and verification time increase

Engineering Contradiction:
Improvemulti-device supportVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system creates a universal user profile that can be associated with multiple device identifiers. This single profile serves as the authentication anchor for all devices, allowing users to access their account from multiple devices without requiring separate authentication mechanisms for each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates references or pointers from multiple device identifiers to a single user profile. Instead of duplicating authentication data across devices, the system maintains one master profile and establishes logical connections from each device to this profile, simplifying verification while supporting multi-device access.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9521139B2System for managing multi-user sign-on in a segmented network
Publication Date: 2016.12.13 BANK OF AMERICA CORP
  • US9521139B2 patent drawing
  • US9521139B2 patent drawing
  • US9521139B2 patent drawing

AI summary

Disclosed is a system for providing multi-user management for personal computing devices over an entity network. The system is typically configured to (i) receive a first request from the personal computing device to receive first user-specific information, (ii) authenticate the user identifier associated with the first user, (iii) associate the user identifier associated with the first user with the device identifier, (iv) communicate a first response to the personal computing device based on authenticating the user identifier, (v) receiving a second request from the personal computing device to receive second user-specific information associated with the first user for a second application, (vi) determining that the device identifier is associated with the user identifier associated with the first user, (vii) and communicating a second response to the personal computing device based on determining that the device identifier is associated with the user identifier associated with the first user.