Persistent Authenticated Device Network for Cross-Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face increasing difficulty in managing multiple passwords for accessing restricted resources, leading to an inefficient and antiquated authentication process.

Innovation Solution

A persistent authenticated device network is established, where user authentication information is shared among devices, allowing access to restricted resources without the need for repeated authentication, by authenticating users, determining their ongoing authentication status, and providing authentication information to downstream devices attempting to access restricted resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users authenticate separately on each device to access restricted resources, then security is maintained, but user convenience deteriorates and authentication burden increases

Engineering Contradiction:
ImproveUser convenience in accessing resourcesVSAvoidNumber of passwords to manage
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The system segments the authentication process by introducing a dedicated authentication device that separates credential management from resource access. The authentication device stores credentials securely and provides them to downstream devices, allowing users to authenticate once rather than managing multiple passwords across different devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication device that acts as a mediator between the user's credentials and downstream computing devices. This intermediary device receives authentication credentials from the user, validates them, and then provides access tokens to downstream devices, eliminating the need for users to directly manage multiple passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication credentials are shared across multiple devices, then user convenience improves, but security risks increase

Engineering Contradiction:
ImproveEase of accessing resources across devicesVSAvoidSecurity of authentication credentials
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication by validating user credentials on the authentication device before any downstream devices receive access tokens. This preliminary action ensures that only authenticated users can obtain access tokens, maintaining security while enabling convenient cross-device access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of sharing actual authentication credentials across multiple devices, the system creates and distributes copied access tokens that are valid for a specific time period. These tokens can be used by downstream devices to access resources without exposing the original credentials, thus maintaining security while enabling convenient access.

Inventive Principle:
Principle #26Copying

3Reliability

If traditional authentication methods are used, then security is maintained, but time consumption increases due to repeated authentication

Engineering Contradiction:
ImproveSecurity validationVSAvoidTime spent on authentication
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes continuous authentication by issuing time-limited access tokens that remain valid for a predetermined period. During this period, downstream devices can access resources without requiring repeated authentication, maintaining security validation while eliminating time consumption associated with repeated login processes.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The authentication device performs preliminary credential validation and issues access tokens in advance. This preliminary action eliminates the need for repeated authentication during the token's validity period, significantly reducing the time users spend on authentication while maintaining security through the predetermined validation process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9923896B2Providing access to a restricted resource via a persistent authenticated device network
Publication Date: 2018.03.20 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US9923896B2 patent drawing
  • US9923896B2 patent drawing
  • US9923896B2 patent drawing

AI summary

Providing access to a restricted resource via a persistent authenticated device network, including: authenticating a user; joining a persistent authenticated device network; iteratively, upon the expiration of a predetermined period of time, determining whether the user remains authenticated; responsive to determining that the user remains authenticated, determining whether a downstream computing device in the persistent authenticated device network is attempting to access a restricted resource; and responsive to determining that the downstream computing device in the persistent authenticated device network is attempting to access a restricted resource, providing user authentication information to the downstream computing device.