Network Device Authentication Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional authentication systems for cloud-based applications can be cumbersome and insecure, particularly for devices like internet-enabled TVs and Blu-ray players that lack user interfaces, and require separate authentication on multiple devices within a network.

Innovation Solution

A network device, such as a router, stores and manages user authentication credentials, detects communications with cloud-based applications, and completes the authentication process by providing the credentials to an identity provider, thereby facilitating access without the need for users to enter credentials on each device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication systems are used on each endpoint device, then security is maintained through credential verification, but usability deteriorates because devices like TVs and Blu-ray players lack suitable user interfaces for authentication

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network device acts as an intermediary between endpoint devices and cloud-based applications. It stores authentication credentials and automatically provides them during authentication processes, eliminating the need for users to manually enter credentials on devices without suitable interfaces while maintaining security through centralized credential management

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If separate authentication processes are required on multiple devices within a network, then each device can verify user identity independently, but time consumption increases due to repeating authentication on each device

Engineering Contradiction:
Improveaccess efficiencyVSAvoidauthentication time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

Authentication credentials are pre-stored on the network device in a secure manner. When a user attempts to access a cloud-based application from any endpoint device, the network device automatically detects the authentication requirement and provides the pre-stored credentials, eliminating the need to repeat the authentication process on each device

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network device provides universal authentication support across multiple endpoint devices and cloud-based applications. A single authentication credential stored on the network device can be used to authenticate users accessing various cloud services from different devices within the network, making the authentication system multi-functional and device-agnostic

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If authentication credentials are stored on endpoint devices, then local authentication can be performed, but security risk increases due to exposure on devices without secure storage or interfaces

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The network device serves as a secure intermediary that stores authentication credentials in a protected environment. Endpoint devices do not need to store or handle credentials directly, reducing their attack surface. The network device manages credential distribution securely during authentication processes, protecting against unauthorized access and interception

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication credential management function is extracted from endpoint devices and centralized on the network device. This separation removes the security burden from endpoint devices, which may lack secure storage capabilities or protected interfaces, and concentrates security controls in a more suitable location with enhanced protection mechanisms

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9544287B1Systems and methods for performing authentication at a network device
Publication Date: 2017.01.10 GEN DIGITAL INC
  • US9544287B1 patent drawing
  • US9544287B1 patent drawing
  • US9544287B1 patent drawing

AI summary

The disclosed computer-implemented method for performing authentication at a network device may include (1) storing, at a network device that handles traffic for at least one endpoint device within a network, an authentication credential associated with a user of the endpoint device, (2) detecting, at the network device, a communication between the endpoint device within the network and a cloud-based application outside the network, (3) determining, at the network device, that access to the cloud-based application is protected by an authentication process, and (4) causing the network device to complete at least a portion of the authentication process for the user by providing the authentication credential associated with the user from the network device to an identity provider of the cloud-based application. Various other methods, systems, and computer-readable media are also disclosed.