Gray List Third-Party Authentication Service Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current white and black lists in communication systems are inadequate for implementing real-time third-party authentication and service control, particularly in scenarios where dynamic service provision is required, as they fail to accurately differentiate between legitimate and malicious service requests and cannot manage third-party authentication effectively.

Innovation Solution

The introduction of a gray list that includes attributes such as the requesting party, authenticating party, and service, allowing for third-party authentication by forwarding service requests to the authenticating party for verification, and dynamically updating based on the authenticating party's requests, enabling real-time service control and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If white list and black list rules are used for service control, then service security is improved, but the system cannot implement real-time third-party authentication and dynamic service control

Engineering Contradiction:
Improveservice securityVSAvoidreal-time third-party authentication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the traditional binary whitelist/blacklist system into three distinct lists: whitelist for authorized services, blacklist for blocked services, and graylist for services requiring third-party authentication. This segmentation allows the system to handle different service control scenarios with appropriate mechanisms, enabling both security and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The graylist acts as an intermediary mechanism between the whitelist and blacklist. When a service request falls into the graylist category, it triggers third-party authentication through an intermediary authentication server, which then determines whether to grant or deny access. This intermediary mechanism enables real-time dynamic control without compromising the security of the whitelist/blacklist system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If gray list is used to intercept spam and require re-sending, then service control accuracy is improved, but malicious attackers can be mistakenly granted access by re-sending requests after time interval

Engineering Contradiction:
Improveservice control accuracyVSAvoidauthentication security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary that processes graylist requests. Instead of automatically granting access after a time interval, the system forwards authentication requests to the authentication server, which verifies the requester's identity and intent. This intermediary verification step prevents malicious attackers from exploiting the re-sending mechanism while maintaining accurate service control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the authentication server provides authentication results back to the service control system. The authentication server analyzes authentication information and provides feedback on whether to grant or deny service requests, enabling continuous improvement of service control accuracy while maintaining security through verified feedback loops.

Inventive Principle:
Principle #23Feedback

3Device complexity

If traditional whitelist and blacklist are used, then system simplicity is maintained, but third-party authentication and real-time service control cannot be implemented

Engineering Contradiction:
Improvesystem structure simplicityVSAvoidthird-party authentication capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent divides the service control system into three distinct lists (whitelist, blacklist, graylist) with clearly defined functions. This segmentation maintains relative system simplicity by organizing control mechanisms into manageable categories while enabling advanced features like third-party authentication through the graylist mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The graylist mechanism serves multiple functions: it acts as a buffer between whitelist and blacklist, enables third-party authentication, provides real-time service control, and maintains system security. This multi-functionality allows the system to implement complex authentication capabilities without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9680811B2Method and system for implementing third-party authentication based on gray list
Publication Date: 2017.06.13 ALCATEL LUCENT SA
  • US9680811B2 patent drawing
  • US9680811B2 patent drawing
  • US9680811B2 patent drawing

AI summary

A communication method and system for implementing third-party authentication is disclosed. The method includes the steps of receiving a service request from a requesting party; performing a third-party authentication on the service request according to a gray list and obtaining an authentication result; and processing the service request according to the authentication result. The system includes one or more processing elements, for example, user equipment (UE), Proxy Call Session Control Function (PCSCF), Service Call Session Control Function (SCSCF) and Application Server (AS) which cooperate to perform the disclosed method. The present invention implements a third-party control of services based on the gray list, and can effectively manage a variety of services in the communication system.