Object Authentication via Central Authorization Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems for non-human machines and objects require point-to-point communications and human intervention, limiting their ability to use a single credential to access multiple services, which is inefficient and insecure.

Innovation Solution

Implementing a system that allows non-human machines and objects to use authorization tokens, such as access tokens, obtained from a trusted central authorization server without human input, using passwords or certificates to validate identities and access services from multiple providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If objects use point-to-point authentication for each service, then security verification is performed, but system complexity increases and automation is limited

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a central authorization server as an intermediary between objects and service providers. The server issues authorization tokens that objects can present to multiple service providers, eliminating the need for point-to-point authentication while maintaining security. This mediator approach reduces system complexity by centralizing authentication management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authorization token serves multiple functions across different service providers, allowing a single credential to work universally across the network. The token can be presented to any service provider that recognizes the authorization server, enabling one object to access multiple services without separate authentication mechanisms for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If objects use multiple credentials for different services, then access control is maintained, but ease of operation decreases

Engineering Contradiction:
Improveaccess controlVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authorization token is designed as a universal credential that can be presented to multiple service providers across the network. A single token, issued by a trusted authorization server, provides access control while simplifying the operation for objects that need to interact with multiple services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple authentication credentials into a single authorization token. Instead of requiring objects to manage separate credentials for each service, the token consolidates authentication information from the authorization server, making access easier while maintaining security controls.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If human intervention is required for authentication, then security is verified, but productivity decreases

Engineering Contradiction:
Improveauthentication verificationVSAvoidautomation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Objects automatically obtain authorization tokens from the authorization server and present them to service providers without human intervention. The system enables self-service authentication where machines communicate directly using tokens, eliminating the need for human users to manually authenticate each interaction while maintaining verification security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authorization server performs preliminary authentication and issues tokens in advance, allowing objects to automatically authenticate subsequent interactions without real-time human intervention. This preliminary verification enables automated operations while maintaining security, as the token was already validated by the authorization server before being issued.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11943215B1Object authentication
Publication Date: 2024.03.26 CITIGROUP TECHNOLOGY INC
  • US11943215B1 patent drawing
  • US11943215B1 patent drawing
  • US11943215B1 patent drawing

AI summary

Machines, devices, and other objects are configured to use authorization tokens to verify object identities without human input. In examples, the object uses a password to validate the object's identity to an authorization server to obtain an access token for use in multiple applications. In another example, the object uses a certificate to validate the object's identity to an authorization server to obtain an access token. In other examples, any other suitable identifying data may be used to validate the object's identity to an authorization server to obtain an access token. The process of using passwords, certificates, or other validation processes to obtain tokens or other authorization mechanisms allows the object to authenticate themselves without human interaction and to use a single identity to access services from multiple service providers that trust a central authorization server.