Shared Authentication Token for Multi-Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face challenges in securely and efficiently managing shared credential authentication across various resources, requiring users to provide multiple login credentials for different services, which can be cumbersome and insecure due to the lack of a unified authentication mechanism.

Innovation Solution

A shared authentication token system is implemented, where a client information handling system and a mobile information handling system communicate to verify an authenticated state, allowing access to resources only when the shared authentication token is valid, ensuring secure and streamlined access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate login credentials are required for different services, then each service can be accessed securely, but the authentication process becomes cumbersome and user experience deteriorates

Engineering Contradiction:
Improveservice access securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple separate authentication credentials into a single shared authentication token that can be used across multiple services. The authentication system merges the verification processes of different services so that one authenticated session can grant access to multiple resources, eliminating the need for users to manually enter multiple separate credentials while maintaining security through centralized token validation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared authentication token is designed to serve multiple functions across different services and resources. Instead of creating service-specific credentials, the system implements a universal authentication mechanism where a single token can authenticate access to various services, making the authentication system multi-functional and reducing operational complexity for users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate login credentials are maintained for different services, then each service has its own authentication control, but the system complexity and security management burden increase

Engineering Contradiction:
Improveauthentication controlVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication control mechanisms into a single centralized authentication system. Instead of maintaining separate credential verification processes for each service, the system combines them into one unified authentication flow that issues a shared token, reducing system complexity while preserving authentication control through centralized policy enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared authentication token acts as an intermediary that mediates between the user and multiple services. Instead of each service directly managing separate credentials, the token serves as a universal intermediary that carries authentication information across service boundaries, simplifying the overall system architecture while maintaining granular access control through token validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional separate authentication mechanisms are used for each service, then each service can be independently secured, but the overall security posture weakens due to multiple credential exposure points

Engineering Contradiction:
Improveservice-level securityVSAvoidcredential exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges multiple credential exposure points into a single shared authentication token. Instead of users managing and potentially exposing multiple separate credentials across different services, the system consolidates authentication into one token, reducing the attack surface and credential exposure risk while maintaining service-level security through centralized token validation and revocation capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11240239B2Apparatus and method for shared credential authentication
Publication Date: 2022.02.01 DELL PROD LP
  • US11240239B2 patent drawing
  • US11240239B2 patent drawing

AI summary

An authentication system for providing shared credential authentication includes a client information handling (IHS) system having a resource service application, and a mobile IHS having a shared authentication application. The shared authentication token indicates that an authenticated state between the client IHS and the mobile IHS exists. The resource service application receives a request to access the resource, and sends an authentication request to an authentication server to authorize access to the resource. The shared authentication application receives a query from the authentication server to verify a status of a shared authentication token, and, when the shared authentication token is valid, responds to the query that the shared authentication token is valid. The resource service application further receives a response to the authentication request, and grants access to the resource when the authentication token indicates that the shared authentication token is valid.