Person-Based Authorization Tokens for Shared Account Personalization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing shared account systems for voice interface devices and IoT devices lack personalization for individual users, leading to generic interactions and inability to differentiate between users, resulting in inadequate customization and privacy concerns.
Innovation Solution
Implement person-based authorization by using voice recognition, face recognition, or other methods to authenticate individual users, generating tokens with both account and person identifiers to enable personalized interactions and data sharing with third-party applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a shared account system is used for multiple users, then device accessibility and sharing capability are improved, but user personalization and privacy protection deteriorate
Solution Approach 1:
The patent segments the authentication system into two distinct layers: account-level authentication (for device access) and person-level authentication (for personalization). This segmentation allows the system to simultaneously support multiple users accessing a shared device while maintaining individual user profiles and preferences, thereby resolving the contradiction between device sharing capability and user personalization.
Solution Approach 2:
The patent introduces a new dimension of person identification beyond traditional account authentication. By adding person-level identifiers (such as voice prints, facial recognition data, or other biometric data) to the existing account layer, the system enables personalized experiences for each user without compromising the shared access model. This dimensional expansion allows simultaneous achievement of both device sharing and user personalization.
2Ease of manufacture
If person-based authentication is implemented, then user personalization and privacy control are improved, but system complexity and authentication time increase
Solution Approach 1:
The patent implements preliminary action by pre-enrolling user biometric data (voice prints, facial recognition data, etc.) and creating person profiles before actual authentication occurs. During authentication, the system simply compares the captured biometric data against the pre-stored templates, significantly reducing computational complexity and authentication time. This pre-processing approach maintains user personalization capabilities while minimizing the complexity burden during runtime.
Solution Approach 2:
The patent introduces person identifiers and person profiles as intermediary elements between the user and the application layer. These intermediaries carry person-specific information without requiring complex real-time processing. The person identifier acts as a lightweight mediator that enables personalized data retrieval and application behavior without adding significant system complexity, thus resolving the contradiction between personalization and system complexity.
3Device complexity
If traditional account-based authentication is used, then system simplicity is maintained, but user differentiation and personalized data access are lost
Solution Approach 1:
The patent implements a nested authentication structure where person-level identification is embedded within the account-level authentication framework. The person identifier is nested within the account context, allowing the system to maintain the simplicity of account-based authentication while internally incorporating person-specific differentiation. This nesting enables user-specific data access and personalization without requiring a complete overhaul of the existing authentication system.
Data Source
AI summary
Disclosed are various embodiments for person-based authorization for shared account systems. In one embodiment, a service receives a user request from a client device associated with an account to perform an action using an application. The service then identifies a user originating the user request. The service generates a token that includes an account identifier corresponding to the account and a person identifier corresponding to the user. The service sends the user request and the token to a provider of the application.


