Authentication via Traffic Flow Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication methods relying on usernames and passwords are inefficient and insecure, as users often reuse passwords, leading to security breaches and forgotten or misplaced credentials.

Innovation Solution

Implementing authentication using traffic flow information, such as protocol identifiers and network addresses, which allows for user verification through traffic flow data aggregation and comparison, reducing reliance on traditional password-based systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password authentication is used, then user access control is achieved, but security risks increase due to password reuse and hacking

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword hacking and reuse risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with a network-based authentication system that uses traffic flow information. Instead of relying on users to manage passwords, the system automatically captures and analyzes network traffic patterns (source IP, destination IP, protocol, port, packet size) to generate device identifiers and authenticate users, thereby eliminating password-related security risks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the user device and the service provider. This server captures traffic flow information, generates device identifiers, and performs authentication, replacing the direct password-based authentication mechanism and providing a secure intermediate layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If password-based authentication is implemented, then user verification is achieved, but user convenience deteriorates due to forgotten or misplaced credentials

Engineering Contradiction:
Improveauthentication convenienceVSAvoidtime lost due to forgotten passwords
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs automatic authentication based on captured traffic flow information without requiring user intervention to recall or enter passwords. The authentication server automatically generates device identifiers from network traffic and verifies them, making the authentication process transparent and convenient for users while eliminating time loss associated with password management

Inventive Principle:
Principle #25Self-service

3Reliability

If traffic flow information authentication is implemented, then security and efficiency are enhanced, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server performs multiple functions: capturing traffic flow information, generating device identifiers, storing authentication data, and verifying credentials. By consolidating these functions into a single multi-functional system rather than separate components, the patent manages complexity while achieving secure authentication

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10097546B2Authentication of a user device using traffic flow information
Publication Date: 2018.10.09 VERIZON PATENT & LICENSING INC
  • US10097546B2 patent drawing
  • US10097546B2 patent drawing
  • US10097546B2 patent drawing

AI summary

A device may receive traffic flow information that includes user device identifiers. The device may receive, from a user device accessing an application associated with a third party service, an authentication request to authenticate the user device with a third party device that provides the third party service. The request may include a session token that identifies a session, an application identifier that identifies the application, and a user device identifier that identifies the user device. The device may determine to authenticate the user device based on whether the user device identifier matches one of the user device identifiers included in the traffic flow information. The device may provide, to the third party device, the session token and an indication of whether the user device has been authenticated to permit the third party device to allow or deny access to the third party service.