Shared Authentication Token for Multi-Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information handling systems face challenges in securely and efficiently managing shared credential authentication across various resources, requiring users to provide multiple login credentials for different services, which can be cumbersome and insecure due to the lack of a unified authentication mechanism.
Innovation Solution
A shared authentication token system is implemented, where a client information handling system and a mobile information handling system communicate to verify an authenticated state, allowing access to resources only when the shared authentication token is valid, ensuring secure and streamlined access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple separate login credentials are required for different services, then each service can be accessed securely, but the authentication process becomes cumbersome and user experience deteriorates
Solution Approach 1:
The patent combines multiple separate authentication credentials into a single shared authentication token that can be used across multiple services. The authentication system merges the verification processes of different services so that one authenticated session can grant access to multiple resources, eliminating the need for users to manually enter multiple separate credentials while maintaining security through centralized token validation.
Solution Approach 2:
The shared authentication token is designed to serve multiple functions across different services and resources. Instead of creating service-specific credentials, the system implements a universal authentication mechanism where a single token can authenticate access to various services, making the authentication system multi-functional and reducing operational complexity for users.
2Reliability
If multiple separate login credentials are maintained for different services, then each service has its own authentication control, but the system complexity and security management burden increase
Solution Approach 1:
The patent merges multiple authentication control mechanisms into a single centralized authentication system. Instead of maintaining separate credential verification processes for each service, the system combines them into one unified authentication flow that issues a shared token, reducing system complexity while preserving authentication control through centralized policy enforcement.
Solution Approach 2:
The shared authentication token acts as an intermediary that mediates between the user and multiple services. Instead of each service directly managing separate credentials, the token serves as a universal intermediary that carries authentication information across service boundaries, simplifying the overall system architecture while maintaining granular access control through token validation.
3Reliability
If traditional separate authentication mechanisms are used for each service, then each service can be independently secured, but the overall security posture weakens due to multiple credential exposure points
Solution Approach 1:
The patent merges multiple credential exposure points into a single shared authentication token. Instead of users managing and potentially exposing multiple separate credentials across different services, the system consolidates authentication into one token, reducing the attack surface and credential exposure risk while maintaining service-level security through centralized token validation and revocation capabilities.
Data Source
AI summary
An authentication system for providing shared credential authentication includes a client information handling (IHS) system having a resource service application, and a mobile IHS having a shared authentication application. The shared authentication token indicates that an authenticated state between the client IHS and the mobile IHS exists. The resource service application receives a request to access the resource, and sends an authentication request to an authentication server to authorize access to the resource. The shared authentication application receives a query from the authentication server to verify a status of a shared authentication token, and, when the shared authentication token is valid, responds to the query that the shared authentication token is valid. The resource service application further receives a response to the authentication request, and grants access to the resource when the authentication token indicates that the shared authentication token is valid.

