Presence Server Token Authentication Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In secure communication networks, especially mobile ones, the frequent need to reestablish connections and enter credentials makes it impractical to implement a secure presence feature, as users must repeatedly authenticate and provide passwords, which is cumbersome and inefficient.
Innovation Solution
A system where a device establishes a secure connection with a presence server using a randomly generated token as a shared-secret, allowing future presence communications over secure or non-secure connections without re-entering credentials, with the token expiring based on defined conditions and being refreshed when a new secure connection is established.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure communication network requires password authentication for every connection establishment, then security is maintained, but user operation becomes cumbersome and impractical
Solution Approach 1:
The patent implements preliminary authentication by establishing a secure connection and exchanging cryptographic credentials (certificate, private key, encrypted shared secret) before actual presence information exchange. This one-time preliminary setup stores security credentials in secure device memory, eliminating the need for repeated password entries while maintaining security. The device performs authentication in advance and caches the results for subsequent connections.
Solution Approach 2:
The patent introduces a presence server as an intermediary that facilitates secure authentication and credential management between devices. The server acts as a trusted mediator that verifies device identities, manages shared secrets, and enables secure presence information exchange without requiring direct password authentication between end devices. This intermediary handles the complex security operations transparently.
2Adaptability or versatility
If frequent connection reestablishment is required in mobile networks, then network adaptability is improved, but authentication overhead increases significantly
Solution Approach 1:
The patent performs authentication and credential exchange in advance during the initial secure connection establishment. The device stores cryptographic credentials in secure memory for reuse. When connections need to be reestablished due to mobile network conditions, the device can quickly reconnect using pre-stored credentials without repeating the full authentication process, thus reducing authentication overhead while maintaining network adaptability.
Solution Approach 2:
The patent maintains continuous presence information exchange by keeping secure connections established as long as possible and using persistent credentials stored in device memory. Rather than breaking and re-authenticating for each connection, the system maintains continuous authenticated sessions where possible, and uses pre-stored security credentials to rapidly reestablish connections when mobile network conditions require reconnection.
3Reliability
If password storage is avoided in device memory for security, then security is improved, but authentication frequency increases
Solution Approach 1:
The patent introduces a presence server as a trusted intermediary that manages authentication credentials and shared secrets. Instead of storing passwords in device memory or requiring frequent re-entry, the server acts as a secure mediator that verifies device identities and manages authentication state. The server stores encrypted credentials securely and handles authentication requests, reducing the authentication burden on client devices while maintaining strong security through centralized credential management.
Data Source
AI summary
This invention includes a system and method to enable a device to determine the presence information of another device over a secure communication network. First, the device and a presence server establish a secure connection. Next, while the initial secure connection with the presence server is established, the device generates a randomly created token and provides it to the presence server. The token is used as a shared-secret by the device and the presence server to secure future presence communications over a non-secure connection. Next, without the need to again enter a password or establish a secure connection with the presence server, the device uses the shared-secret to sign, encrypt and convey presence information to the presence server over an arbitrary connection. Finally, the presence server may share the first device's presence information with another device.


