BLE Credential Sharing via Encrypted Containers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current OTT media service authentication methods consume significant computing and network resources, and can be frustrating for users due to forgotten credentials and cumbersome reset procedures, with risks of interception when sharing credentials over the internet or via cloud-based systems.

Innovation Solution

Implementing a method to share credentials between devices using a short-range wireless communication protocol, such as Bluetooth Low Energy (BLE), allowing devices to establish a connection, verify credentials, and store them securely on the receiving device, thereby reducing resource consumption and interception risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credentials are shared over the internet or via cloud-based systems, then credential sharing functionality is achieved, but security risk increases due to potential interception

Engineering Contradiction:
Improvecredential sharing functionalityVSAvoidinterception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a cloud-based credential sharing system as an intermediary that securely manages and transmits credentials between devices. The system uses encrypted credential containers that are generated, stored, and exchanged through controlled cloud operations, allowing credential sharing functionality while mitigating interception risks through the security infrastructure of the intermediary system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cloud-based credential sharing is implemented, then credential sharing capability is provided, but computing and network resources are consumed

Engineering Contradiction:
Improvecredential sharing capabilityVSAvoidcomputing and network resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by pre-generating and storing encrypted credential containers in the cloud before they are needed for sharing. When a user needs to share credentials, the pre-prepared encrypted containers can be quickly retrieved and transmitted, reducing the computing and network resources required at the moment of sharing compared to generating and transmitting raw credentials in real-time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional authentication methods are used, then user authentication is achieved, but user frustration increases due to forgotten credentials and reset procedures

Engineering Contradiction:
Improveuser authenticationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service credential sharing mechanism where users can autonomously share their credentials with other devices through the cloud system without requiring support staff or complex reset procedures. The system automatically manages the credential container lifecycle, including generation, storage, retrieval, and revocation, allowing users to simply initiate sharing without dealing with password recovery or account management complexities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10834594B1Systems and methods for authentication sharing
Publication Date: 2020.11.10 VERIZON PATENT & LICENSING INC
  • US10834594B1 patent drawing
  • US10834594B1 patent drawing
  • US10834594B1 patent drawing

AI summary

A first device may discover, using a short-range wireless communication protocol, an authentication service advertised by a second device, and may establish, with the second device, a connection using the short-range wireless communication protocol. The first device may display, after establishing the connection with the second device, a first identifier, and may provide to the second device a confirmation request including the first identifier to permit the second device to determine whether a second identifier, input by a user into the second device, matches the first identifier. The first device may receive, from the second device, encrypted credentials to authenticate the user to access a service based on the second device determining whether the second identifier matches the first identifier. The first device may decrypt the encrypted credentials to obtain credentials, and may authenticate, using the credentials, the user to access the service.