Network-Assisted Authentication for Secondary Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing service provider systems face challenges in authenticating users accessing services via secondary devices that lack authentication tokens, particularly when location determination is difficult or impossible, and maintaining user privacy while providing location-based services.

Innovation Solution

A network-assisted authentication procedure where a wireless network authenticates a primary device on behalf of a secondary device, using identifiers and location information to verify user access and provide services to the secondary device without requiring additional user interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a user attempts to access services via a secondary device without authentication tokens, then service accessibility is improved, but security and authentication reliability deteriorate

Engineering Contradiction:
Improveservice accessibilityVSAvoidauthentication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a network entity (e.g., location service, authentication server) as an intermediary to facilitate authentication between the secondary device and service provider. The network entity receives authentication requests from the secondary device, retrieves subscriber information from the primary device's profile, and performs verification without requiring direct authentication tokens on the secondary device. This mediator enables service access while maintaining security through network-assisted verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network-assisted authentication is implemented, then authentication reliability is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing multi-functional network entities (such as location services, authentication servers, or profile management systems) to perform authentication functions. These entities already serve multiple purposes in the network infrastructure, so reusing them for authentication purposes avoids adding dedicated new components. The solution integrates authentication capabilities into existing universal network functions, reducing overall system complexity while maintaining reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If location information is obtained for service delivery, then service personalization is improved, but user privacy is compromised

Engineering Contradiction:
Improveservice personalizationVSAvoiduser privacy
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by processing and utilizing location information in a localized and controlled manner within the network infrastructure. Rather than collecting and storing comprehensive user location data centrally, the system retrieves only the specific location information needed for immediate service delivery from the network entity, uses it for personalized service provision, and does not retain it long-term. This localized processing minimizes privacy exposure while enabling service personalization.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12549548B2Systems and methods for network-assisted authentication and location services
Publication Date: 2026.02.10 VERIZON PATENT & LICENSING INC
  • US12549548B2 patent drawing
  • US12549548B2 patent drawing
  • US12549548B2 patent drawing

AI summary

A system described herein may receive a first authentication request that includes a first identifier of a User Equipment (“UE”), and a second identifier of a second device. The system may output a second authentication request to a wireless network with which the UE is associated, which may include the first identifier of the UE. The system may receive, in response to the second authentication request an indication that the UE has been authenticated, and location information associated with the UE. The system may identify one or more services associated with the received location of the UE, and may output, to the second device and based on the response to the second authentication request, traffic associated with the identified one or more services.