Routing Device for Cross-Provider User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face challenges in centrally managing personal information across multiple services, leading to difficulties in authenticating users when their data is not managed by a single server device.

Innovation Solution

A routing device that communicates with center devices to store and manage linking information between attributes and users, allowing it to acquire the relevant attribute for a user and request authentication from the corresponding center device, enabling authentication even when the user's data is not managed by the initial center device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If personal information is centrally managed by one server device, then authentication efficiency is improved, but system adaptability deteriorates when user data is distributed across multiple services

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsystem adaptability
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The patent introduces a routing device as an intermediary between the authentication server and multiple service provider systems. This routing device stores linking information that maps users to their respective attribute data locations, enabling the authentication server to efficiently route authentication requests to the correct data sources without requiring centralized storage of all user information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If user data is distributed across multiple service provider systems, then system adaptability is improved, but authentication complexity increases

Engineering Contradiction:
Improvesystem adaptabilityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The routing device performs preliminary action by pre-storing linking information that associates users with their attribute data locations before authentication is needed. This pre-established mapping allows the authentication server to quickly determine where to find user data without complex real-time discovery processes, reducing authentication complexity while maintaining support for distributed data across multiple services.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If centralized management of personal information is implemented, then ease of operation is improved, but information security deteriorates when sensitive data is accessed across services

Engineering Contradiction:
Improveease of operationVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments personal information into different attribute data sets stored at different service provider systems based on sensitivity and service requirements. The routing device manages these segmented data locations, allowing the authentication server to access only the specific attributes needed for authentication rather than centrally storing or accessing all user information, thereby improving information security while maintaining ease of operation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240129303A1Routing device, management center device, user authentication method, and storage medium
Publication Date: 2024.04.18 DENSO CORP
  • US20240129303A1 patent drawing
  • US20240129303A1 patent drawing
  • US20240129303A1 patent drawing

AI summary

A routing device communicable with a first center device and a second center device related to providing a service to a first vehicle linked with a first user and a second vehicle linked with a second user is provided. The routing device is configured to store first linking information that links a first attribute and a first user belonging to the first attribute, and second linking information that links a second attribute and a second user belonging to the second attribute, acquire the second attribute corresponding to the second user, and request the second center device corresponding to the second attribute to perform an authentication process of the second user.