Session Transfer System for Seamless Cross-Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the inconvenience of having to re-authenticate and restart their e-commerce application sessions across multiple electronic devices, such as smartphones, tablets, and desktops, while also wanting to transfer the activity state seamlessly, which current systems fail to address effectively.

Innovation Solution

A system and method for securely transferring authenticated sessions and states between electronic devices by determining if the target device is trusted based on user behavior, device registration, and security levels, allowing seamless continuation of activities without re-authentication, while maintaining session security through consent-based transfers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authenticated sessions are transferred between electronic devices, then user convenience and continuity of activity are improved, but security risks increase due to potential unauthorized access

Engineering Contradiction:
Improveuser convenienceVSAvoidsession security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a session management server as an intermediary between the first and second electronic devices. This server receives session transfer requests, validates device trust status, manages authentication credentials, and coordinates the session transfer process. By acting as a mediator, the server enables convenient session transfers while maintaining centralized security control, thus resolving the contradiction between user convenience and session security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements device trust determination and registration processes that occur before session transfers are permitted. Devices must be pre-validated as trusted through behavior analysis, registration with the session management server, and security level assessment. This preliminary action ensures that only authenticated sessions are transferred to verified devices, preventing unauthorized access while maintaining convenient transfer capabilities for legitimate devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If session transfer requires device trust verification, then session security is improved, but transfer time and operational complexity increase

Engineering Contradiction:
Improvesession securityVSAvoidtransfer time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs device trust verification, behavior analysis, and security level assessment in advance before session transfers are needed. Devices are pre-registered and validated with the session management server, establishing trust relationships beforehand. When a session transfer is initiated, the verification process is expedited because the foundational trust assessment has already been completed, thus reducing transfer time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates and manages session state copies that can be rapidly transferred between devices. Instead of performing complex authentication and verification at the moment of transfer, the system prepares session state representations in advance that can be quickly replicated and activated on trusted devices. This copying mechanism reduces transfer time while the underlying trust verification ensures security.

Inventive Principle:
Principle #26Copying

3Ease of operation

If seamless session transfer is enabled across devices, then user experience is improved, but system complexity increases due to authentication management

Engineering Contradiction:
Improveuser experienceVSAvoidauthentication management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts authentication management complexity from the individual electronic devices and centralizes it in a dedicated session management server. The server handles device registration, trust determination, behavior analysis, security level assessment, and session state management. Individual devices only need to communicate transfer requests and receive session states, significantly reducing their authentication management complexity while enabling seamless transfers across multiple devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The session management server is designed as a universal system that handles multiple functions: device registration, trust verification, behavior analysis, security level management, session state storage, and transfer coordination. This multi-functional approach consolidates complexity into a single system that can serve multiple devices and sessions, reducing overall system complexity compared to implementing these functions in each individual device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10783565B2Method, manufacture, and system of transferring authenticated sessions and states between electronic devices
Publication Date: 2020.09.22 EBAY INC
  • US10783565B2 patent drawing
  • US10783565B2 patent drawing
  • US10783565B2 patent drawing

AI summary

In various example embodiments, a system and method for transferring an authenticated session of an application running on one electronic device to a second electronic device after determining the second electronic device is a trusted device are presented. In one embodiment, an instruction is received to transfer an authenticated session of an application running on a first device associated with a user account to a second device associated with the user account. The second device is verified to be associated with the user account of the first device. The second device is determined to be a trusted device of an authorized user of the user account. The authenticated session of the application running on the first device is transferred to the second device to reproduce a current state of the authenticated session on the second device.