Temporary Access Token for Secure Shared Terminal Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In shared computing environments, the security and convenience of accessing resources are compromised when users share devices, as the shared terminals lack access to all features and capabilities due to the limitations of existing screen casting and mirroring methods, and the risk of unauthorized access to remote computing sessions increases when long-lived access tokens are not properly managed.

Innovation Solution

A method is implemented where a mobile device establishes a communications channel with a shared computing terminal, using a temporary access token to enable the terminal to access a remote computing session without transferring the user's long-lived access token, allowing secure and convenient access to workspace resources by authenticating through a code and pairing mechanism, such as QR code or NFC, which expires after a set time or for a single session.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a long-lived access token is transferred from the mobile device to the shared computing terminal, then the terminal can access remote computing resources, but the security risk increases due to potential unauthorized access

Engineering Contradiction:
Improveaccess capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the access token functionality by introducing a temporary access token that is separate from the long-lived access token. The temporary token is generated specifically for the shared computing terminal and has limited scope and duration, while the long-lived token remains securely stored in the mobile device. This segmentation allows the terminal to access resources without exposing the permanent credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a disposable temporary access token that is valid only for a specific duration or single use. This temporary token can be discarded after use or expiration, eliminating the security risk associated with long-lived tokens being exposed on shared devices. The temporary token serves its purpose and then becomes obsolete, similar to a disposable key.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Adaptability or versatility

If screen casting or mirroring methods are used on shared terminals, then access to remote computing resources is enabled, but feature limitations and poor user experience occur

Engineering Contradiction:
Improveresource accessVSAvoidfeature capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where the mobile device acts as a mediator between the shared computing terminal and the remote computing resources. The mobile device generates a temporary access token that the terminal uses to directly authenticate with the resource provider, bypassing the need for screen casting or mirroring. This intermediary approach enables full feature access while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11889000B2Shared device secure access
Publication Date: 2024.01.30 CITRIX SYSTEMS INC
  • US11889000B2 patent drawing
  • US11889000B2 patent drawing
  • US11889000B2 patent drawing

AI summary

A method includes operating a mobile device to establish a communications channel between the mobile device and a shared computing terminal. The shared computing terminal is accessible to a plurality of users other than a user of the mobile device. In response to authentication of the user of the mobile device with a remote computing device, the mobile device receives a code from the remote computing device. The mobile device provides the code to the shared computing terminal via the communications channel to enable the shared computing terminal to request a temporary access token from the remote computing device. The temporary access token is used by the shared computing terminal to launch a computing session with the remote computing device without transfer of a long-lived access token of the user from the mobile device to the shared computing terminal.