Delegated Device Authentication With Context-Based Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network environments face challenges in authenticating and authorizing devices, particularly in complex systems like IoT and cloud computing, where spoofing can lead to security breaches, and existing systems struggle to manage complex device interactions and policy updates effectively.

Innovation Solution

A third-party server is delegated to manage authentication and authorization, determining device identities, generating interaction control lists, and providing policy recommendations through a guided workflow, using namespace management and blockchain technology to ensure secure device interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a system administrator manually manages device authentication and authorization in complex network environments, then security control and policy management are maintained, but the system becomes difficult to manage and scale as device relationships become increasingly complex

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a third-party server as an intermediary between devices in the network. This server automatically performs authentication and authorization by receiving authentication queries from recipient devices, determining authenticity based on transmitter device identities, and returning authentication results. This intermediary approach resolves the contradiction by maintaining security control through automated verification while eliminating the burden of manually managing complex device relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables recipient devices to autonomously perform authentication by querying the third-party server with transmitter device identities. The recipient device receives authentication results and automatically determines whether to trust the transmitter device without administrator intervention. This self-service mechanism maintains security while simplifying management by empowering devices to handle their own authentication needs.

Inventive Principle:
Principle #25Self-service

2Reliability

If automated authentication systems are implemented to prevent spoofing, then security against malicious entities is improved, but the complexity of managing authentication queries and responses across multiple devices increases

Engineering Contradiction:
Improveanti-spoofing capabilityVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The third-party server acts as a centralized intermediary that receives authentication queries from recipient devices and returns authentication results. This approach prevents spoofing by verifying transmitter device identities through a trusted third party while simplifying the authentication management complexity by centralizing the verification logic in one server rather than requiring each device to independently manage complex authentication relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback mechanism where recipient devices send authentication queries to the third-party server and receive authentication results as feedback. This feedback loop enables automated decision-making about device trustworthiness, improving anti-spoofing capability while reducing management complexity by replacing manual authentication decisions with automated feedback-based responses.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If manual policy updates are performed for each device interaction, then precise control over device relationships is maintained, but the time and effort required to update policies in complex multi-device systems increases significantly

Engineering Contradiction:
Improvepolicy control precisionVSAvoidpolicy update time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system enables automatic policy application where recipient devices autonomously determine whether to trust transmitter devices based on authentication results from the third-party server. This self-service approach maintains precise policy control by automatically applying authentication rules without requiring manual policy updates for each device interaction, thereby eliminating the time loss associated with manual policy management in complex multi-device systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The third-party server serves as an intermediary that automatically manages authentication policies by verifying device identities and returning authentication results. This intermediary mechanism maintains precise policy control through centralized verification while eliminating the need for manual policy updates across multiple devices, significantly reducing the time and effort required to manage policies in complex network environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If decentralized authentication approaches are used where each device manages its own authentication, then system autonomy is improved, but security vulnerabilities to spoofing and impersonation increase

Engineering Contradiction:
Improvesystem autonomyVSAvoidspoofing vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The third-party server acts as a trusted intermediary that recipient devices query to verify transmitter device identities. This approach maintains system autonomy by allowing devices to independently perform authentication through the server while eliminating spoofing vulnerabilities by replacing decentralized trust decisions with centralized verification through a trusted third party.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback-based authentication where recipient devices receive authentication results from the third-party server and automatically adjust their trust decisions accordingly. This feedback mechanism maintains system autonomy by enabling devices to make independent authentication decisions based on verified information while eliminating spoofing vulnerabilities through centralized verification feedback.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4094417B1Automated authentication and authorization in a communication system
Publication Date: 2026.02.25 VALIMAIL INC
  • EP4094417B1 patent drawingFigure 1A
  • EP4094417B1 patent drawingFigure 1B
  • EP4094417B1 patent drawingFigure 1C

AI summary

An application-operating organization may delegate a third-party server to serve as an automated contextual authentication responder and an authorization responder. The third-party server may manage a delegated section of the organization's namespace that includes the public identities of various devices controlled by the organization. The third-party server may also dynamically generate interaction control list that is tailored to a requesting device's context based on the interaction control policies set forth by the organization. The interaction control list may include information that determines the authorization of the requesting device to interact with another device. The third-party server may also automatically determine the role of a new device to which existing policies are inapplicable and provide guided workflow for the organization to set up new interaction control policies in governing the new device. The determination of the roles of devices may be based on an iterative process using external data sources.