Dynamic Authentication Token Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Subscribers of telecommunication devices face inconvenience and security risks due to managing multiple credentials manually, and service providers incur costs in providing credentials, while existing authentication methods do not effectively distribute authentication sessions across time periods, leading to high loads on authentication servers.

Innovation Solution

An automated authentication service that uses a telecommunication device's SIM to authenticate with an authentication service, generating an authentication token with a dynamically determined expiry time based on expected server load and user behavior to distribute authentication sessions evenly throughout the day.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication tokens have fixed expiry times, then users can manually manage credentials, but authentication sessions cluster at certain times causing high server load

Engineering Contradiction:
ImproveManual credential managementVSAvoidAuthentication session distribution
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent applies dynamics by making the authentication token expiry time configurable and adjustable based on expected server load. Instead of fixed expiry times, the system dynamically determines appropriate expiry durations to distribute authentication sessions more evenly across different time periods, preventing clustering at specific times while maintaining operational ease for users.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If service providers provide credentials to users, then authentication is simplified, but service providers incur high costs

Engineering Contradiction:
ImproveAuthentication processVSAvoidCredential distribution cost
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent implements self-service by enabling users to authenticate automatically using credentials stored on their own telecommunication devices (such as SIM cards). The authentication service on the network facilitates this process, allowing users to independently authenticate without service providers manually distributing credentials, thereby simplifying the authentication process while eliminating the high costs associated with credential distribution.

Inventive Principle:
Principle #25Self-service

3Quantity of substance

If users manually manage multiple credentials, then service providers save costs, but users experience inconvenience and security risks

Engineering Contradiction:
ImproveCredential management costVSAvoidCredential management
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent introduces an authentication service as an intermediary between users and multiple services. This service stores and manages authentication credentials on the user's telecommunication device, allowing automatic authentication across multiple services without users manually handling multiple credentials. This reduces user inconvenience and security risks while maintaining cost efficiency for service providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If authentication sessions are concentrated at certain times, then user convenience is improved, but authentication servers experience high load

Engineering Contradiction:
ImproveAuthentication accessibilityVSAvoidServer load
Core Design Contradiction:
Ease of operationVSPower

Solution Approach 1:

The patent applies dynamics by configuring authentication token expiry times to distribute sessions away from peak periods. The system adjusts expiry durations based on expected server load patterns, ensuring that authentication sessions are spread more evenly throughout the day, thereby reducing peak server load while maintaining continuous authentication accessibility for users.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9590987B2Dynamic distribution of authentication sessions
Publication Date: 2017.03.07 T MOBILE US INC
  • US9590987B2 patent drawing
  • US9590987B2 patent drawing
  • US9590987B2 patent drawing

AI summary

This disclosure relates to authenticating and providing transport security over unsecured IP networks to network subscribers. The system includes an authentication service that authenticates network subscribers. The authentication service can dynamically define expiry times for network authentication.