Single Sign-On Session Token Distribution for Multi-Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face the burden of multiple device authentication across various computing devices and the emerging Internet of Things (IoT) landscape, necessitating a solution for secure, accessible data storage that facilitates single sign-on across multiple devices.
Innovation Solution
The system establishes a login session for a user account and provides a session token to a device associated with the user account, allowing access to resources without reauthentication, using modules such as a sign-on module, session module, communication module, verification module, and access module to manage authentication and access requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users authenticate to each device individually, then security is maintained, but user convenience deteriorates due to repeated authentication burden
Solution Approach 1:
The patent segments the authentication process by separating device authentication from user authentication. The system authenticates each device individually to the user's account, creating device-specific credentials that allow multiple devices to access resources without requiring the user to re-authenticate on each device. This resolves the contradiction by maintaining security through individual device authentication while improving convenience through single user authentication.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the system acts as a mediator between the user and multiple devices. After the user authenticates once, the system generates and distributes device credentials to multiple devices, serving as an intermediary that manages authentication state across devices. This eliminates repeated authentication requirements while maintaining security through the intermediary's control over credential distribution.
2Adaptability or versatility
If cloud-based data storage is implemented, then data accessibility is improved, but authentication complexity increases across multiple devices
Solution Approach 1:
The patent implements a universal authentication approach where a single user authentication event grants access credentials to multiple devices simultaneously. The system creates a multi-functional authentication mechanism that works across desktops, laptops, tablets, smartphones, and IoT devices. This resolves the contradiction by enabling universal data accessibility across all devices while simplifying authentication to a single action rather than device-specific authentication processes.
3Speed
If session tokens are stored on multiple devices, then access speed is improved, but security risk increases if tokens are compromised
Solution Approach 1:
The patent applies local quality by creating device-specific credentials tailored to each individual device's security context and trust level. Rather than using identical session tokens across all devices, the system generates customized authentication credentials for each device based on its specific characteristics, security posture, and user authorization. This allows fast access on trusted devices while maintaining security by having different credential characteristics for different devices.
Solution Approach 2:
The patent changes authentication parameters dynamically based on device characteristics, security context, and usage patterns. Session tokens and credentials are generated with varying parameters (such as expiration times, scope limitations, and security requirements) tailored to each device. This enables optimized access speed for trusted devices while maintaining security through parameterized credential design that adapts to each device's risk profile.
Data Source
AI summary
The disclosed computer-implemented method for facilitating single sign-on for multiple devices may include (1) establishing a login session for a user account, (2) in response to establishing the login session, providing, to a device associated with the user account, a session token for the user account, (3) receiving, from at least one client, a request to access resources associated with the user account, (4) determining that the associated device possesses the session token for the user account, and (5) in response to determining that the associated device possesses the session token, providing, to the client, access to the resources associated with the user account. Various other methods, systems, and computer-readable media are also disclosed.


