Gateway Authentication via Physical Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identity theft over the Internet poses a risk as communication devices' private information can be stolen and used to access services without authorization, necessitating a system for authenticating communication devices.

Innovation Solution

A system and method that involves a controller element receiving authentication requests from communication devices, utilizing physical associations between gateways and network elements to authenticate devices by matching provided IDs with stored authentication IDs, ensuring only authorized devices access services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication devices use private information (MAC address, serial number) for network access, then device identification and network connectivity are achieved, but identity theft and unauthorized access to services occur

Engineering Contradiction:
Improveauthentication securityVSAvoididentity theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway as an intermediary component between the communication device and the packet-switched network. The gateway performs authentication by verifying the physical association between the communication device and itself, and between the gateway and network elements. This intermediary mechanism prevents direct use of stolen private information for unauthorized access, as the gateway validates each connection attempt against stored authentication IDs before allowing network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication actions before allowing network access. The gateway stores authentication IDs in advance and uses them to verify communication devices before permitting service access. This preliminary verification prevents identity theft from succeeding, as unauthorized devices are blocked before they can access services, even if they possess stolen private information.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a physical association between gateway and network elements is enforced, then unauthorized access is prevented, but system complexity increases due to additional authentication mechanisms

Engineering Contradiction:
Improveaccess controlVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway is designed as a multi-functional component that performs multiple tasks: it acts as a network access point for communication devices, performs authentication by verifying physical associations, stores and manages authentication IDs, and controls service access. By consolidating these functions into a single gateway component, the patent reduces overall system complexity compared to having separate authentication servers, physical association verification systems, and access control mechanisms distributed throughout the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10470103B2System and method for authentication of a communication device
Publication Date: 2019.11.05 AT&T INTELLECTUAL PROPERTY I L P
  • US10470103B2 patent drawing
  • US10470103B2 patent drawing
  • US10470103B2 patent drawing

AI summary

A system and method for authentication of a communication device is disclosed. A system that incorporates teachings of the present disclosure may include, for example, an authentication system can have a controller element that receives from a communication device by way of a packet-switched network an authentication request comprising a first identification (ID) of a virtual gateway and a second ID of the communication device. The virtual gateway and at least one network element of the packet-switched network can be provisioned to have a physical association with each other such that other network elements of the packet-switched network deny services to the virtual gateway when the virtual gateway attempts to operate outside of said physical association. From said physical association and the aforementioned IDs the controller element can authenticate the communication device. Additional embodiments are disclosed.