Unified Access Device Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogeneous computing environments, users face inconvenience due to the need to provide different user credentials for multiple applications on various devices, leading to repeated authentication processes, which complicates access control and hinders usability.

Innovation Solution

A method and system that utilize a device identifier to authenticate users once, allowing subsequent applications to access platforms without requiring additional credentials, by storing a login identifier associated with the device identifier and expiring it for security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users provide credentials for each application separately, then security is maintained through individual authentication, but user convenience deteriorates due to repeated authentication processes

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges multiple application credentials into a single device-level credential. The access device stores a unified credential associated with the device identifier that can be used by multiple applications, eliminating the need for separate credentials while maintaining security through centralized authentication management

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal credential system where a single credential stored at the access device can serve multiple applications. The device identifier-based credential acts as a multi-functional key that enables different applications to access their respective services without requiring application-specific credentials

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple credentials are stored for different applications, then application-specific access control is improved, but device complexity increases due to credential management

Engineering Contradiction:
Improveapplication-specific access controlVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts credential management from the individual applications and centralizes it at the access device. Instead of each application managing its own credentials, the access device stores and manages all credentials centrally, associating them with the device identifier, thereby reducing the complexity burden on individual applications and the user device

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access device serves as an intermediary between the user device and multiple applications. It mediates authentication by storing credentials associated with the device identifier and providing them to applications as needed, simplifying the overall system architecture by introducing a centralized credential management layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10154035B2System and method for controlling access
Publication Date: 2018.12.11 OPEN TEXT SA ULC
  • US10154035B2 patent drawing
  • US10154035B2 patent drawing
  • US10154035B2 patent drawing

AI summary

Systems and methods for controlling access to multiple applications on a computing device are provided. One embodiment of a system includes an access device configured to: receive a request to access a first application and a device identifier; authenticate the user using a user credential associated with the user and store the device identifier in association with a login identifier in response to authentication of the user. The access device can be further configured to receive a request to access a second application and the device identifier. The access device can allow access to the second application based on the previous authentication of the user.