Federated Authentication via Platform Account Manager

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-screen video architectures face challenges in securely and efficiently managing content distribution and user authentication across diverse devices, leading to issues with content accessibility and entitlement verification.

Innovation Solution

A system implementing federated/cooperative authentication and digital rights management, where user devices are registered through a platform account manager that initiates authentication with a partner system, and a DRM server manages content delivery and entitlement rights, ensuring secure and device-specific content access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If federated authentication with partner systems is implemented, then user authentication security is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a platform account manager as an intermediary component that coordinates authentication between user devices and multiple partner systems. The account manager receives authentication requests, redirects users to appropriate partner systems, and consolidates authentication results, thereby improving security through federated authentication while managing system complexity through centralized coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device-specific content access is enforced, then content security is improved, but content accessibility across devices deteriorates

Engineering Contradiction:
Improvecontent securityVSAvoidcontent accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments content access rights by registering specific user devices with the system and associating each device with unique entitlements. The DRM server issues device-specific license keys that enable secure content access on registered devices while preventing access on unregistered devices, thus maintaining security while enabling multi-device accessibility for authorized users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal account management system that allows a single user account to be associated with multiple different device types (mobile phones, tablets, PCs, set-top boxes). The platform account manager handles device registration and entitlement verification across diverse device platforms, enabling users to access content universally across their personal devices while maintaining device-specific security controls.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If DRM license verification is performed, then content protection is improved, but content delivery speed deteriorates

Engineering Contradiction:
Improvecontent protectionVSAvoidcontent delivery speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs DRM license verification as a preliminary action before content delivery. The DRM server validates the license key and device entitlements in advance, and only after successful verification does the system initiate content streaming. This preliminary verification ensures content protection while allowing fast content delivery once authentication is complete, as subsequent content transfer proceeds without repeated verification overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8763154B2Federated authentication
Publication Date: 2014.06.24 VERIZON PATENT & LICENSING INC
  • US8763154B2 patent drawing
  • US8763154B2 patent drawing
  • US8763154B2 patent drawing

AI summary

A system may receive, at a site, a first message for authentication from a browser hosted on a user device; send, from the site, a redirect universal resource locator of a partner system to the browser; receive a response from the partner system via the browser, the response including a second message indicating whether an authentication of a user of a first device, at the partner system, was successful; determine whether the authentication has been successful based on the second message; and register the first device when it is determined that the authentication has been successful based on the second message.