Mobile Device Authentication Payload Management for Untrusted Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication service providers face challenges in authenticating and authorizing access to premium services over untrusted networks, particularly for mobile devices that are not subscribed to cellular wireless communication services, which can lead to security concerns and increased traffic loads on trusted networks.

Innovation Solution

A method and system that involve a mobile communication device requesting an authentication payload from a media gateway via a cellular wireless communication link, storing it, and using it to access premium services over an untrusted network, while ensuring authentication and authorization through a two-step process involving a session manager and authentication server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile devices access premium services over untrusted networks, then service accessibility and user convenience are improved, but security risks and authentication complexity increase

Engineering Contradiction:
Improveservice accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a media gateway as an intermediary component that bridges the untrusted network and the trusted network infrastructure. The media gateway performs authentication and authorization functions, acting as a mediator that allows mobile devices to access premium services over untrusted networks while maintaining security through controlled authentication processes and payload verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication payloads are verified for each service request, then security is improved, but network traffic load and processing overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication where the media gateway verifies the authentication payload once during the initial service request. The gateway checks whether the payload is present and valid, and only then allows subsequent service requests to proceed without repeated verification overhead. This preliminary check approach maintains security while reducing processing load for ongoing service delivery.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If trusted network infrastructure is used for all premium service delivery, then authentication reliability is improved, but network resource consumption and cost increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by allowing different network paths for different purposes: untrusted networks are used for delivering premium service content (bandwidth-consuming services like streaming video), while the trusted network infrastructure is only engaged for critical authentication and authorization functions through the media gateway. This differentiated approach reduces overall network resource consumption while maintaining authentication reliability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9154955B1Authenticated delivery of premium communication services to trusted devices over an untrusted network
Publication Date: 2015.10.06 T MOBILE INNOVATIONS LLC
  • US9154955B1 patent drawing
  • US9154955B1 patent drawing
  • US9154955B1 patent drawing

AI summary

A mobile communication device. The device comprises a cellular radio transceiver, a processor, a memory, and an application stored in the memory. When executed by the processor, the application receives an input that initiates access to a premium communication service via an untrusted network, determines whether an authentication payload is stored in the memory. When the application determines it is not stored in the memory, it transmits via the cellular radio transceiver to a media gateway a request to execute a service provided by an authorization server, receives an authentication payload from the media gateway via the cellular ratio transceiver, stores the authentication payload in the memory, and accesses the premium communication service initiated by the input based on the authentication payload stored in the memory.