AI Identity Service for Zero Trust Wireless Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise computing environments face challenges in ensuring information security and preventing unauthorized access, particularly with the proliferation of wireless devices and increased bandwidth in zero trust computing environments, where conventional security measures are inadequate to handle the scale and complexity of 5G networks.

Innovation Solution

A computing platform equipped with an artificial-intelligence engine that generates profiles for connection requests, assigns identities to user devices, and continuously monitors behavior, using machine-learning models to validate connections and enforce policies, thereby ensuring secure access to enterprise resources while managing the increased load of 5G networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security measures are used to protect enterprise networks, then implementation is simple and cost-effective, but they are inadequate to handle the scale and complexity of 5G networks and wireless devices

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity service as an intermediary component that sits between wireless devices and enterprise resources. This identity service handles authentication, authorization, and device identity management, effectively mediating security concerns without requiring complex changes to the entire network infrastructure. The identity service translates security requirements into manageable identity verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal identity service that handles multiple security functions including authentication, authorization, account management, and device identity verification. This multi-functional approach consolidates what would otherwise require multiple separate security systems, reducing overall complexity while maintaining comprehensive security coverage for 5G networks and diverse wireless devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If continuous authentication is implemented in zero trust environments, then security is improved, but the processing load and complexity increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary device registration and identity provisioning before devices connect to the enterprise network. During this preliminary phase, devices are assigned unique identities and baseline security credentials. This preliminary action reduces the complexity of continuous authentication by establishing trust relationships in advance, so that ongoing authentication can rely on pre-configured identity verification rather than complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the identity service continuously monitors device behavior, connection patterns, and authentication events. This feedback is used to dynamically adjust authentication requirements and device identities based on observed behavior. The feedback loop enables the system to maintain high security while adapting to normal device operations, reducing unnecessary authentication complexity for trusted devices.

Inventive Principle:
Principle #23Feedback

3Productivity

If 5G wireless networks are deployed to increase bandwidth and connection speed, then network performance is improved, but the number of connection requests and devices increases, amplifying security challenges

Engineering Contradiction:
Improvenetwork bandwidthVSAvoidsecurity management capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent enables devices to self-register and self-provision identities with the identity service upon connecting to the 5G network. Devices automatically obtain unique identifiers and security credentials without requiring manual configuration or complex approval processes. This self-service capability allows the network to scale to handle increased device connections while maintaining consistent security management, as each device independently establishes its identity relationship with the enterprise.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11381972B2Optimizing authentication and management of wireless devices in zero trust computing environments
Publication Date: 2022.07.05 BANK OF AMERICA CORP
  • US11381972B2 patent drawing
  • US11381972B2 patent drawing
  • US11381972B2 patent drawing

AI summary

Aspects of the disclosure relate to optimizing authentication and management of wireless devices in zero trust computing environments. In some embodiments, a computing platform may receive, from a user computing device, a connection request. Subsequently, the computing platform may generate, using an artificial-intelligence engine, a profile for the connection request. Based on the profile for the connection request generated using the artificial-intelligence engine, the computing platform may determine that the connection request is valid. In response to determining that the connection request is valid, the computing platform may establish a connection with the user computing device. Based on establishing the connection with the user computing device, the computing platform may assign an identity to the user computing device. After assigning the identity to the user computing device, the computing platform may monitor behavior of the user computing device based on the identity assigned to the user computing device.