Transient Session Token for Communal Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users often forget to log out of their accounts on communal devices, leading to unauthorized access and modifications, which can alter their personalized experiences and incur unintended charges.

Innovation Solution

A media streaming device initiates a transient session that allows users to access applications without providing credentials, using a transient session token with an expiration parameter to automatically terminate the session, ensuring secure and private access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users access applications on communal devices using traditional login methods, then they can maintain their individualized experience, but they risk unauthorized access and modifications if they forget to log out

Engineering Contradiction:
Improveaccount securityVSAvoidlogin convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a transient session token as an intermediary between the user and the application account. Instead of directly logging in with credentials, the user receives a temporary token that grants limited access. This mediator prevents direct credential exposure while maintaining account security and automatic session termination.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent employs transient session tokens that are short-lived and automatically expire after use. These disposable tokens replace persistent login credentials, ensuring that even if forgotten, the access automatically terminates after a set period, eliminating the risk of unauthorized prolonged access.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Ease of operation

If users provide credentials for authentication, then they can access their accounts, but personal information may remain on the device and be compromised

Engineering Contradiction:
Improveauthentication capabilityVSAvoidcredential exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication capability from the traditional credential-based system. Instead of requiring username and password input, the system uses device-based authentication where the user's device proves identity without transmitting actual credentials to the communal device, removing the harmful element of credential storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication intermediary process where the user's device and the server communicate to verify identity without exposing credentials to the communal device. The transient session token serves as a mediator that confirms authentication without storing sensitive information on the communal device.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If users manually log out after each session, then account security is maintained, but this requires user awareness and action that may not always occur

Engineering Contradiction:
Improvesession terminationVSAvoiduser action requirement
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring automatic session termination through transient tokens with expiration parameters. The session is designed to end automatically after use or after a predetermined time period, eliminating the need for user-initiated logout actions while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service session management where the transient session token automatically handles termination without user intervention. The system serves itself by automatically expiring sessions based on predefined conditions, removing the burden of manual logout from the user.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If the device stores user profile and account information for personalized experience, then user preferences are maintained, but unauthorized users can modify these settings

Engineering Contradiction:
Improvepersonalization capabilityVSAvoidunauthorized modification
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses transient session tokens that are short-lived and single-use. These disposable tokens grant temporary access to personalized content without allowing modifications to account settings. The transient nature ensures that even if unauthorized access occurs, the window for modification is extremely limited and automatically closes.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent implements partial action by providing users with only the necessary permissions for content access during the transient session, while restricting modification capabilities. The authentication is sufficient for viewing personalized content but excessive for making changes, creating a controlled access model that protects account settings.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230370502A1Transient setup of applications on communal devices
Publication Date: 2023.11.16 APPLE INC
  • US20230370502A1 patent drawing
  • US20230370502A1 patent drawing
  • US20230370502A1 patent drawing

AI summary

Techniques are disclosed for initiating transient sessions on a communal device. An example method includes a device detecting a user device within a threshold distance of the device. The device can transmit control instructions to the user device for a response from the user device based on the detection, the response comprising an indication as to whether to initiate a transient session of a streaming service. The device can transmit, to an application server, a request for a transient session token based on the response from the user device. The device can receive, from the application server, the transient session token, the transient session token including an expiration parameter. The device can initiate the transient session based on the transient session token, the transient session comprising presenting content provided by the application server on a presentation device. The device can terminate the transient session based on the expiration parameter.