Ticket-Based Device Authentication in Deployable Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a deployable computing environment, users face inefficiencies in authenticating devices every time they connect and perform operations, and there is a need for a secure method to represent and manage relationships between users and devices for secure data sharing and synchronization.
Innovation Solution
A technique involving user and device identification tickets, along with device claim tickets, is used to authenticate users and devices, allowing them to securely interact and perform operations within the environment, establishing and managing relationships for secure data sharing and synchronization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user authenticates a device every time it connects to perform operations within the deployable computing environment, then security is maintained, but operational efficiency deteriorates due to repeated authentication requirements
Solution Approach 1:
The system performs preliminary authentication by establishing a relationship between the user and device, where the user specifies they own the device and delegates operations. This preliminary action creates a representation of the relationship that allows the device to perform authorized operations without repeated authentication, resolving the contradiction between security and operational efficiency
2Reliability
If the system establishes secure relationships between users and devices with delegated operations, then authorization security is improved, but system complexity increases due to relationship management overhead
Solution Approach 1:
The system creates a representation (copy) of the relationship between user and device within the deployable computing environment. This representation includes the device identification ticket and authorized operations, allowing the system to manage relationships efficiently without directly managing the complex underlying authentication credentials, thus improving authorization security while managing complexity
3Adaptability or versatility
If multiple users with multiple devices share information through a distributed computing environment, then data synchronization capability is improved, but authentication complexity increases
Solution Approach 1:
The relationship representation serves multiple functions: it authenticates the device, authorizes operations, enables data synchronization, and facilitates peer connectivity. This multi-functional approach allows multiple users with multiple devices to share information and synchronize data without requiring separate authentication mechanisms for each function, improving adaptability while managing authentication complexity
Data Source
AI summary
A deployable computing environment may facilitate interaction and data sharing between users and devices. Users, devices, and relationships between the users and devices may be represented within the deployable computing environment. A relationship between a user and a device may specify that the device is owned by the user and that the device is authorized to perform operations within the deployable computing environment on behalf of the user. Secure authentication of devices and users for interaction within the deployable computing environment is achieved by authenticating tickets corresponding to the user, the device, and the relationship. A device identification ticket and a user identification ticket are used to authenticate the device and user for interaction within the deployable computing environment. A device claim ticket allows the device to perform delegated operations (e.g., data synchronization, peer connectivity, etc.) on behalf of the user without the user's credentials (e.g., user identification ticket).


