Network Device Authentication via Segmented Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access devices, such as routers, face security risks due to unauthorized access when users modify settings, as any connected device can access settings using stolen or hacked user identification information, compromising security.

Innovation Solution

Implementing a validation and authentication process involving a provisioning device and a management device to verify user devices and authenticate users before allowing access, using secure communication sessions and encrypted data storage to protect settings information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If any connected device can access settings using stolen or hacked user identification information, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveaccess to settingsVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple independent components: device validation, user authentication, and authorization. Each component performs a specific security function, creating layered protection that prevents unauthorized access while maintaining legitimate user convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary devices (provisioning device and management device) that mediate between the user device and the network device. These intermediaries validate devices and authenticate users before granting access, preventing direct unauthorized access to settings while allowing legitimate users convenient operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a validation and authentication process involving multiple devices is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex security system is segmented into distinct functional modules: the network device handles authentication decisions, the provisioning device manages device validation, and the management device handles user authentication. This segmentation distributes complexity across multiple specialized components rather than concentrating it in one device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each device in the system performs self-validation and self-authentication functions where possible. The network device validates itself against the provisioning device, and users authenticate themselves against the management device, reducing the need for complex centralized control mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11259186B2Systems and methods for validating a device and authenticating a user
Publication Date: 2022.02.22 VERIZON PATENT & LICENSING INC
  • US11259186B2 patent drawing
  • US11259186B2 patent drawing
  • US11259186B2 patent drawing

AI summary

A device determines information concerning the device and sends the information concerning the device to a first device. The device receives, from the first device, information concerning a user device, and receives, from a second device, a request concerning the user device accessing the device. The request includes information identifying the device and information identifying the user device. The device generates a request response by validating the user device for access to the device based on the request and sends, to the second device, the request response to facilitate a communication session to be established between the user device and the device. The device communicates with the user device via the communication session.