Short-Range Wireless Authorization for Limited Interface Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Client devices with limited user interfaces, such as printers and vending machines, face challenges in securely obtaining access to protected resources without exposing user credentials to potential security risks, especially when shared among multiple users or located in public areas.
Innovation Solution
A method using short-range wireless communication, like NFC, to initiate an authorization flow between a client device and a user's mobile computing device, which then authenticates with an authorization service to obtain a security credential, allowing the client device to access protected resources without requiring direct user input on the client device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If client devices with limited user interfaces are used in public areas or shared among multiple users, then accessibility and ease of operation are improved, but security risk increases due to potential credential exposure
Solution Approach 1:
The patent extracts the authentication interface from the client device and relocates it to the user's mobile computing device. The client device with limited interface receives authentication requests via short-range wireless communication, and the user interacts with the authentication interface on their personal mobile device, thereby removing the security vulnerability of displaying credentials on shared or public client devices.
Solution Approach 2:
The user's mobile computing device serves as an intermediary between the client device and the authorization service. It receives authentication requests from the client device, presents the authorization interface to the user, and relays the user's authentication decisions back to the client device, eliminating the need for credentials to be displayed or entered on the client device itself.
2Reliability
If traditional authorization flows are used requiring direct user input on the client device, then authentication security is maintained, but user convenience deteriorates due to repeated authentication requirements
Solution Approach 1:
The system performs preliminary authentication by establishing a trusted relationship between the client device and the user's mobile device through short-range wireless communication. Once authenticated, the client device can access protected resources without requiring the user to repeatedly input credentials, as the authentication is performed in advance through the mobile device interface.
Solution Approach 2:
The user's mobile device serves itself as the authentication interface for multiple client devices. Once the user has authenticated their identity on their mobile device, it can automatically authorize subsequent authentication requests from trusted client devices without requiring manual credential entry each time, making the system both secure and convenient.
3Ease of operation
If client devices display authentication interfaces, then user interaction is enabled, but credential exposure risk increases in shared or public environments
Solution Approach 1:
The authentication interface is extracted from the client device and displayed on the user's mobile computing device instead. The client device communicates authentication requests and results through short-range wireless communication, but never displays credential fields or authentication forms that could be observed by unauthorized persons.
Solution Approach 2:
The mobile device acts as an intermediary that handles all user interaction for authentication. It receives authentication requests from the client device, displays the authorization interface to the user, collects the user's response, and transmits it back to the client device, eliminating any need for the client device to display sensitive authentication elements.
Data Source
AI summary
In general, aspects of the disclosure are directed towards techniques for initiating an authorization flow with a user to enable a user interface-limited client computing device to obtain access to protected resources hosted by a resource service. In some aspects, a computing device comprises at least one processor. The computing device also comprises a short-range wireless communication module operable by the at least one processor to receive, using short-range wireless communication, an authentication request from a client device. The computing device also comprises an authorization module operable by the at least one processor to receive authorization to provide at least one security credential to the client device, wherein the authorization module is further configured to, responsive to receiving the authorization, send an indication of the authorization to an authentication service.


