CPE-Based Secure Access Channel for Web Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for securing user access to web services over the internet lack seamless authentication mechanisms, particularly for end-users connecting from various devices, and do not effectively prevent credential theft or unauthorized access, especially when attackers steal both credentials and devices.

Innovation Solution

A method and system that establish secure communication channels between customer premise equipment (CPE) and user devices, using CPE-based authentication to ensure that only authorized traffic passes through trusted intermediaries, with end-user or ISP-controlled configurations to enforce different access rights levels, ensuring high-security access without additional user interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 2-step Web access authentication is implemented, then security is improved, but user convenience deteriorates due to additional waiting time and manual code entry

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically performs authentication verification without requiring user intervention. The CPE device autonomously validates credentials and establishes secure channels, eliminating the need for users to manually enter codes or wait for SMS verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The CPE device acts as an intermediary between the user device and service provider, automatically handling authentication processes. This mediator performs credential verification and channel establishment in the background, improving both security and user convenience simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If CPE-based authentication is implemented, then security against credential theft is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against credential theftVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The CPE device serves as a trusted intermediary that centralizes authentication functions. By placing the authentication logic in the CPE rather than distributing it across multiple devices, the system achieves high security while keeping the overall architecture manageable and centralized.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If seamless authentication is implemented, then user convenience is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system operates autonomously in the background through the CPE device, providing seamless user experience while maintaining strict security verification. The system automatically validates credentials and establishes secure channels without user intervention, achieving both convenience and security simultaneously.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3163836B1Method and apparatus for secure access of a service via customer premise equipment
Publication Date: 2020.07.22 INTERDIGITAL CE PATENT HOLDINGS SAS
  • EP3163836B1 patent drawingFigure 1a~1b
  • EP3163836B1 patent drawingFigure 2
  • EP3163836B1 patent drawingFigure 3~4

AI summary

A method for providing a service comprising at a service provider device (116, 118, 1500) that establishes (S1610) a first secure communications channel with a customer premise equipment (106) and establishes (S1620) with a user device (102) a second secure communications channel, passing through the customer premise equipment and the first secure communications channel, upon reception of correct credentials for the user. The service provider device receives (S1630) a request for a service from the user device, verifies (S1640) that the request was received through the second secure communications channel and provides (S1650) the service to the user device through the second secure communications channel only in case the customer premise equipment is part of a set of devices through which the second secure communications channel must pass. The service provider device can also provide (S1660), in response to a request received through the second secure communications channel, a second service to the user device regardless of which the device through which the second secure communications channel passes.