Ticket-Based Device Authentication in Deployable Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a deployable computing environment, users face inefficiencies in authenticating devices every time they connect and perform operations, and there is a need for a secure method to represent and manage relationships between users and devices for secure data sharing and synchronization.

Innovation Solution

A technique involving user and device identification tickets, along with device claim tickets, is used to authenticate users and devices, allowing them to securely interact and perform operations within the environment, establishing and managing relationships for secure data sharing and synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user authenticates a device every time it connects to perform operations within the deployable computing environment, then security is maintained, but operational efficiency deteriorates due to repeated authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication by establishing a relationship between the user and device, where the user specifies they own the device and delegates operations. This preliminary action creates a representation of the relationship that allows the device to perform authorized operations without repeated authentication, resolving the contradiction between security and operational efficiency

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the system establishes secure relationships between users and devices with delegated operations, then authorization security is improved, but system complexity increases due to relationship management overhead

Engineering Contradiction:
Improveauthorization securityVSAvoidrelationship management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates a representation (copy) of the relationship between user and device within the deployable computing environment. This representation includes the device identification ticket and authorized operations, allowing the system to manage relationships efficiently without directly managing the complex underlying authentication credentials, thus improving authorization security while managing complexity

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple users with multiple devices share information through a distributed computing environment, then data synchronization capability is improved, but authentication complexity increases

Engineering Contradiction:
Improvedata synchronization capabilityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The relationship representation serves multiple functions: it authenticates the device, authorizes operations, enables data synchronization, and facilitates peer connectivity. This multi-functional approach allows multiple users with multiple devices to share information and synchronize data without requiring separate authentication mechanisms for each function, improving adaptability while managing authentication complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9967258B2Device authentication within deployable computing environment
Publication Date: 2018.05.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9967258B2 patent drawing
  • US9967258B2 patent drawing
  • US9967258B2 patent drawing

AI summary

A deployable computing environment may facilitate interaction and data sharing between users and devices. Users, devices, and relationships between the users and devices may be represented within the deployable computing environment. A relationship between a user and a device may specify that the device is owned by the user and that the device is authorized to perform operations within the deployable computing environment on behalf of the user. Secure authentication of devices and users for interaction within the deployable computing environment is achieved by authenticating tickets corresponding to the user, the device, and the relationship. A device identification ticket and a user identification ticket are used to authenticate the device and user for interaction within the deployable computing environment. A device claim ticket allows the device to perform delegated operations (e.g., data synchronization, peer connectivity, etc.) on behalf of the user without the user's credentials (e.g., user identification ticket).