Authentication Server for Seamless Third-Party Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Captive portals often create a confusing and undesirable user experience by blocking network access until explicit consent is given, and they fail to provide seamless authentication to third-party networks without user interaction.

Innovation Solution

A system and method that uses an authentication server to automatically authenticate a device to a third-party network using credentials from a mobile application, allowing seamless connection without user interaction, while protecting user privacy by not exposing actual credentials and using shadow credentials for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If captive portals are used to authenticate users to a network, then user permission and agreement to terms and conditions can be acquired, but network access is blocked until the captive portal process is completed, leading to a confusing and undesirable user experience

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-provisioning credentials in the mobile application before the user arrives at the third-party location. When the user enters the coverage area, the device automatically detects the network and initiates authentication using pre-configured credentials, eliminating the need for on-site captive portal interaction and providing seamless access.

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If automatic authentication is implemented using credentials from a mobile application, then seamless connection without user interaction is achieved, but user privacy may be compromised through exposure of actual credentials

Engineering Contradiction:
Improveautomatic authenticationVSAvoiduser privacy
Core Design Contradiction:
Extent of automationVSLoss of information

Solution Approach 1:

The system introduces an intermediary authentication server that acts as a mediator between the mobile application and the third-party network. The authentication server receives credentials from the mobile application, performs authentication, and relays the authentication result to the network. This intermediary architecture allows automatic authentication while protecting user privacy by preventing direct exposure of actual credentials to the third-party network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If third-party credentials are used for automatic authentication, then seamless authentication to third-party networks is enabled, but the credentials may be exposed to the authentication provider

Engineering Contradiction:
Improvethird-party network compatibilityVSAvoidcredentials privacy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The authentication server serves as an intermediary that receives third-party credentials from the mobile application, performs authentication against the third-party network, and obtains authentication results without exposing the actual credentials to the authentication provider. This maintains third-party network compatibility while protecting credentials privacy through the intermediary authentication mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11171956B2Systems and methods for initiating network access according to automatic authentication utilizing a mobile device
Publication Date: 2021.11.09 AT&T INTELLECTUAL PROPERTY I L P
  • US11171956B2 patent drawing
  • US11171956B2 patent drawing
  • US11171956B2 patent drawing

AI summary

In one embodiment, a method includes receiving, by an authentication server, first credentials from a mobile application installed on a device. The first credentials include information associated with the device and information associated with a user of the device. The method also includes automatically receiving, by the authentication server and from the device, a request to connect the device to a network of a third party. The request is automatically generated by the device without interaction from the user of the device and the request comprises second credentials. The method further includes determining, by the authentication server, whether to authenticate the device using the first credentials and the second credentials and communicating, by the authentication server, a packet to the device that allows the device to connect to the network of the third party if the authentication server determines to authenticate the device.