Smart Host Credential Sharing for Secure Multi-User Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern devices, such as in-vehicle infotainment systems and IoT devices, face challenges in securely accessing multiple cloud services without manual login for each account, especially when shared among users, leading to potential data exposure and complexity in managing multiple user profiles.
Innovation Solution
A smart host system that uses personal devices like smartphones as identity keys and data servers, providing access to authorized data through biometric verification, encrypting data with proximity-based keys, and automatically managing account access and data protection, eliminating the need for manual login and ensuring secure, separate user profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual login is required for each cloud service account on every device, then security control is improved, but ease of operation deteriorates
Solution Approach 1:
The patent introduces a smart host device as an intermediary that stores account credentials and provides them to client devices. This mediator enables automatic authentication without users manually entering credentials on each device, thus improving ease of operation while maintaining security control through the centralized credential management system
Solution Approach 2:
The system performs preliminary authentication by storing credentials in advance on the smart host device. When a user needs to access cloud services on a client device, the authentication has already been prepared on the smart host, eliminating the need for manual login and improving operational convenience while maintaining security
2Adaptability or versatility
If multiple user accounts are stored on shared devices, then adaptability is improved, but security deteriorates due to potential data exposure
Solution Approach 1:
The patent segments user credentials and data by storing them on individual smart host devices associated with each user, rather than storing multiple users' credentials on a shared client device. This segmentation ensures that each user's data remains isolated and secure on their personal smart host, while the shared device can still support multiple users through sequential authentication
Solution Approach 2:
The smart host device acts as a secure intermediary that holds user credentials and selectively provides them to client devices. This mediator architecture allows multiple users to access the shared device with their respective credentials stored on their personal smart hosts, enabling multi-user adaptability while maintaining individual security boundaries
3Reliability
If users manually delete data and log out on shared devices, then security is improved, but loss of time increases
Solution Approach 1:
The system implements self-service authentication where the smart host device automatically manages credential provision to client devices. Users simply need to authenticate on their smart host, and the system automatically handles the login process on shared devices, eliminating manual data deletion and logout steps while maintaining security through automated credential management
Data Source
AI summary
Systems, methods, devices, and/or other components to implement cross-platform smart hosting are described. Smart devices or “smart hosts” such as smartphones, smart watches, tablets, etc. may be used as identity keys and/or data servers when associated with connected client devices or “clients” such as in-vehicle infotainment systems, smart televisions, medical systems, internet of things (IoT) devices, industrial devices, etc. The smart host may enable access to personal information and data, such as contacts, calendars, e-mails, history, media, login information for various services, etc. A high degree of protection of personal data may be achieved by not storing login information at the clients and encrypting cached data using keys that are only provided when the smart host is present (e.g., within a specified physical or spatial proximity threshold to a client).


