OS Cloud Credential Token for Unified Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the burden of managing multiple login identities for various cloud service providers and are susceptible to unauthorized applications impersonating genuine ones, leading to security vulnerabilities and cumbersome authentication processes.

Innovation Solution

A system where a client device's operating system uses a universal OS cloud login ID to access multiple cloud services, with a token request sent to an identity provider including the application ID, cloud service ID, and OS cloud credentials, resulting in a token that verifies the application's authenticity and grants access without requiring additional login credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users use separate login credentials for each cloud service provider, then security verification for each service is ensured, but user operation complexity increases and authentication becomes cumbersome

Engineering Contradiction:
Improvesecurity verificationVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple separate authentication processes into a single unified authentication flow. The operating system performs one-time authentication with the identity provider, obtaining a universal token that grants access to multiple cloud services. This eliminates the need for users to repeatedly enter credentials for each service while maintaining security through the token-based verification mechanism.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal authentication token that serves multiple functions across different cloud services. The token, generated by the identity provider, can be used to authenticate access to various cloud services (photo service, video service, music service, etc.) without requiring service-specific credentials, thus providing multi-functional access from a single authentication event.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If cloud services accept any application requesting access, then ease of access is improved, but security vulnerabilities increase due to unauthorized applications impersonating genuine ones

Engineering Contradiction:
Improveapplication accessVSAvoidapplication authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the operating system acts as a mediator between applications and cloud services. The OS validates application credentials and obtains authenticated tokens from the identity provider before granting access to cloud services. This intermediary layer prevents unauthorized applications from directly accessing cloud services while maintaining ease of access for legitimate applications through the automated token process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication where the operating system verifies application credentials and obtains authentication tokens before applications can access cloud services. The identity provider pre-validates the application's legitimacy through credential verification (such as signing certificates), and the resulting token is stored for subsequent access, ensuring that only authenticated applications can interact with cloud services.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9699180B2Cloud service authentication
Publication Date: 2017.07.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9699180B2 patent drawing
  • US9699180B2 patent drawing
  • US9699180B2 patent drawing

AI summary

Providing access to a cloud service includes a system receiving an application request to access a cloud service. In response, the system sends an identity provider (IP) a token request, comprising an application identifier (ID), an operating system (OS) cloud credential associated with login credentials of a user of an OS hosting the application, and a cloud service ID of the cloud service. Based on sending the token request, and on the IP authenticating the user and verifying the application ID is valid, the system receives a token from the IP. The token, which is signed with an IP signature, comprises the cloud service ID, the application ID, and a user assigned ID associated with the cloud service. The system provides the token to the application for submission to a cloud service provider for access, and obtains cloud service access based on the cloud service provider validating the IP signature.