Centralized Authorization Server for Subscriber Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems for network services, particularly for streaming media, face challenges in providing flexible and secure access, as they often require direct authentication with specific service providers and lack universal compatibility with multiple operators, leading to security concerns and limitations in user flexibility.

Innovation Solution

The system authorizes access to network services by obtaining information from a set-top box or subscriber device, verifying user subscriptions, and allowing authentication through a centralized network service that interacts with multiple service providers, enhancing security and flexibility by managing connections directly with subscriber equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct authentication with specific service providers is used, then security is improved, but adaptability to multiple operators deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability to multiple operators
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a centralized authorization server as an intermediary between subscriber devices and multiple service providers. This server obtains authorization information from service providers and makes authorization decisions locally, eliminating the need for direct authentication with each provider while maintaining security. The intermediary handles multiple operator protocols and formats, providing universal compatibility without compromising the security model.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple authentication protocols are supported for universal compatibility, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveuniversal compatibilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authorization server acts as a mediator that handles multiple authentication protocols and formats from different service providers. Instead of embedding multiple protocol implementations in each subscriber device, the server translates and processes various provider-specific formats centrally, significantly reducing device complexity while maintaining universal compatibility across multiple operators.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authorization server is designed as a universal platform that can handle authorization requests from multiple service providers using different protocols. It implements a single standardized interface for subscriber devices while supporting multiple backend provider formats, achieving multi-functionality without increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If centralized authorization server is implemented, then adaptability is improved, but system complexity increases

Engineering Contradiction:
Improveuniversal compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The centralized authorization server consolidates the complexity of handling multiple service provider protocols and authorization logic in a single location. This centralization improves adaptability to multiple operators while managing system complexity through a dedicated infrastructure component rather than distributing complexity across numerous subscriber devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2586200B1Systems and methods for authorizing access to network services using information obtained from subscriber equipment
Publication Date: 2020.10.28 SLING MEDIA INC
  • EP2586200B1 patent drawingFigure 1
  • EP2586200B1 patent drawingFigure 2
  • EP2586200B1 patent drawingFigure 3

AI summary

Systems and methods are described for authorizing access to network service based upon information obtained from a set-top box (STB) or other subscriber equipment associated with the user requesting access to the network service. The network service suitably contacts a subscriber device associated with the user via the network in response to a request for access that is received from the user. Information obtained from the subscriber device is processed to thereby determine if the user is authorized to use the service. If the user is authorized, then the service is provided via the network. Access to an online video stream, for example, can be conditioned upon the requesting user having an appropriate account with a cable, direct broadcast satellite (DBS) or other service that can be verified through contact with the user's STB or other subscriber equipment.