Authentication Extension for Untrusted Devices via Trusted Mobile Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for authenticating premium communication services over untrusted networks are cumbersome, especially for devices lacking accessible keyboards or flexible user interfaces, such as televisions and network appliances, which struggle to input time-sensitive cookies or security codes.

Innovation Solution

A system that leverages a trusted mobile communication device to extend authentication to untrusted devices by matching IP addresses and embedding time-to-live values in cookies, allowing untrusted devices to access premium services without direct user input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods are used for untrusted devices, then security can be maintained, but the authentication process becomes cumbersome and difficult for devices without accessible keyboards or flexible user interfaces

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a trusted mobile communication device as an intermediary to perform authentication on behalf of untrusted devices. The mobile device receives authentication credentials, processes them through the authentication server, and extends authentication to the untrusted device without requiring direct user input on the untrusted device. This mediator approach resolves the contradiction by enabling easy authentication for devices without keyboards while maintaining security through the trusted mobile device's involvement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server performs preliminary actions by pre-storing source IP addresses associated with trusted mobile devices and pre-assigning time-to-live values for authentication extensions. When an untrusted device requests authentication, the server already has the necessary authentication parameters ready, allowing rapid verification without requiring complex real-time authentication procedures. This preliminary preparation simplifies the authentication process for untrusted devices.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If authentication extensions are provided to untrusted devices, then access to premium services is enabled, but the radio access network bears additional authentication burden

Engineering Contradiction:
Improvedevice access capabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The trusted mobile communication device serves as an intermediary that absorbs the authentication burden. Instead of the radio access network directly authenticating each untrusted device, the mobile device's trusted authentication is extended to cover the untrusted device. This intermediary approach enables versatile device access while reducing network resource consumption by leveraging the existing trusted authentication infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server and trusted mobile device create a universal authentication mechanism that can serve multiple functions: authenticating the mobile device itself, extending authentication to multiple untrusted devices, and managing time-to-live values for different devices. This multi-functional approach enables broad device access capability while efficiently managing network resources through a single authentication framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If time-sensitive cookies are required for authentication, then security is maintained, but devices without accessible keyboards or flexible user interfaces cannot provide the necessary input

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted mobile communication device acts as an intermediary that handles the time-sensitive cookie input and authentication processing. The untrusted device does not need to directly input cookies or security codes, as the mobile device's authentication credentials are used to extend authentication to the untrusted device. This maintains security through time-sensitive authentication while eliminating the usability barrier for devices without accessible keyboards.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system provides self-service authentication where the trusted mobile device automatically performs the authentication actions on behalf of the untrusted device. The untrusted device simply needs to be connected to the network, and the authentication server automatically verifies the time-to-live values and extends authentication without requiring any user input or manual cookie entry on the untrusted device.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9319407B1Authentication extension to untrusted devices on an untrusted network
Publication Date: 2016.04.19 T MOBILE INNOVATIONS LLC
  • US9319407B1 patent drawing
  • US9319407B1 patent drawing
  • US9319407B1 patent drawing

AI summary

A server for providing premium communication services via an untrusted network. The server comprises a processor, memory, and an application that is configured to receive a request from an untrusted communication device to access a premium communication service via the untrusted network, wherein the request comprises an internet protocol (IP) address, match the IP address from the request with a previously stored source IP address associated with a message sent by a trusted mobile communication device, wherein the device is authorized to access the premium communication service via the untrusted network, determine if the request is received within a time period indicated by a previously assigned time-to-live value associated with authentication extension, upon determining that the request is received within the indicated time period, generate a cookie associated with the communication device, and send the cookie to the communication device via the untrusted network.