Session Transfer Key for Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In current cloud computing systems, users must manually re-authenticate to access secondary resources from a first computing session, leading to duplicative authentication requests and a diminished user experience due to the lack of shared authentication credentials between virtual machines hosting applications and remote storage providers.

Innovation Solution

A method where a server generates a session transfer key that encapsulates authentication tokens and configuration data, allowing the automatic establishment of a second computing session for a secondary resource without user input, by mapping the session transfer key to a session identifier and providing instructions to the client device to establish this session between the virtual machine and the secondary resource provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual re-authentication is required for secondary resources, then security is maintained through separate authentication credentials, but user experience deteriorates due to duplicative authentication requests

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a session transfer key as an intermediary mechanism that bridges the first computing session (hosting the application) and the second computing session (accessing secondary resources). This session transfer key contains embedded authentication credentials that enable automatic authentication without requiring users to re-enter credentials, thus resolving the contradiction between maintaining security through separate authentication and providing seamless user experience

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by embedding authentication credentials into the session transfer key before the user needs to access secondary resources. The authentication credentials are prepared and packaged in advance within the session transfer key structure, allowing the second computing session to be established automatically without requiring real-time user authentication input

Inventive Principle:
Principle #10Preliminary action

2Reliability

If separate authentication credentials are used between virtual machines and remote storage providers, then security boundaries are maintained, but authentication efficiency decreases due to lack of credential sharing

Engineering Contradiction:
Improvesecurity boundariesVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The session transfer key is structured as a nested container that encapsulates authentication credentials within it. The authentication credentials are nested inside the session transfer key structure, which itself is generated by the server. This nested structure allows secure credential transmission while maintaining the security boundary between different computing sessions and resource providers

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The session transfer key acts as an intermediary carrier that transports authentication credentials from the first computing session to the second computing session. This intermediary mechanism enables credential sharing between virtual machines and remote storage providers while maintaining security boundaries, thereby improving authentication efficiency without compromising security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automatic session establishment is implemented, then user experience is enhanced by eliminating manual input, but system complexity increases due to session transfer key generation and mapping

Engineering Contradiction:
Improveuser experienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically establishing the second computing session without requiring user input. The client device uses the session transfer key to automatically authenticate and establish connections with secondary resources. This automation eliminates manual authentication steps while the server handles the complexity of session transfer key generation and credential management in the background

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11750527B2Method and system for sharing user configuration data between different computing sessions
Publication Date: 2023.09.05 CITRIX SYSTEMS INC
  • US11750527B2 patent drawing
  • US11750527B2 patent drawing
  • US11750527B2 patent drawing

AI summary

A method includes receiving a request from a client device to establish a first computing session for a first resource hosted on a virtual machine (VM). The method includes generating a session transfer key for accessing a second resource provided by a second resource provider. The method includes issuing instructions, to the VM that hosts the first resource, for establishing a second computing session to host the second resource, wherein the instructions include a mapping of the session transfer key to a session identifier. The method includes providing the instructions to the client device to establish the second computing session for the second resource without input for the second resource from the user of the client device. The establishment of the second computing session being between the VM and the second resource provider and based on the mapping of the session transfer key to the session identifier.