Anonymous Network Access Profiles for Shared Mobile Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Management of different credentials for multiple mobile communication devices and network access is complex, requiring tracking unique usernames and passwords for each device, which complicates authentication processes.
Innovation Solution
Implementing a communication management system that assigns a shared, anonymous access profile with common credentials to multiple devices, allowing them to access a network using an anonymous username and password, and managing access through a policy server that enforces access policies based on these credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If unique credentials are assigned to each mobile communication device, then network security and device identification are improved, but credential management complexity increases
Solution Approach 1:
The patent merges the credentials of multiple mobile communication devices into a single shared credential set. Instead of managing unique credentials for each device, the system allows multiple devices to authenticate using the same username and password, thereby reducing credential management complexity while maintaining network security through centralized authentication control
Solution Approach 2:
The patent creates universal credentials that can be used by any number of mobile communication devices to access the network. The shared username and password serve multiple devices simultaneously, eliminating the need for device-specific credential management while maintaining authentication reliability
2Ease of operation
If separate authentication is performed for each device, then device-specific access control is improved, but authentication processing time increases
Solution Approach 1:
The patent combines multiple device authentication processes into a single shared authentication event. When one device authenticates with the shared credentials, the authentication result can be leveraged for other devices, reducing redundant authentication processing time while maintaining access control precision through centralized policy enforcement
3Loss of information
If unique credentials are tracked for each device, then accountability and auditing are improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary authentication management system that handles credential tracking and device identification. Instead of directly tracking credentials for each device, the intermediary system maintains a mapping between devices and the shared credentials, simplifying the tracking mechanism while preserving accountability and auditing capabilities
Data Source
AI summary
A same wireless access profile is installed on each of multiple mobile communication devices. The wireless access profile includes outer identity information and anonymous inner identity information for each service. The anonymous inner identity information includes a credential used by each of the multiple mobile communication devices to use the service. To use the service such as access a remote network, a respective mobile communication device communicates an anonymous username and password assigned to the service to a policy server during first level authentication. The policy server stores a network address of the authenticated mobile communication device. During second level authentication, the policy server receives an identity of the mobile communication device from a network gateway. The policy server provides access control information (assigned to the service) to the network gateway. The network gateway then provides access to the mobile communication device in accordance with the access control information.


