Network Device Authentication via Device Identifier Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing communication between user equipment (UE) and application devices in cellular networks, especially those requiring high security, are either costly or vulnerable to unauthorized access when using proprietary UEs or VPN connections, and credentials can be easily compromised.

Innovation Solution

Implementing a network device that authenticates UEs based on preemptively authorized device identifiers, providing a signature for successful authentication, which allows the application device to verify and grant access, thereby reducing the need for expensive high-security protocols and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary UEs or VPN connections are used to ensure high security, then security level is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network device as an intermediary between the UE and application device. The network device performs authentication by verifying device identifiers against a list of authorized identifiers, and provides signatures for successful authentication. This intermediary approach allows standard UEs to achieve high security without implementing complex proprietary protocols or VPN connections, thereby resolving the contradiction between security level and device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces complex mechanical authentication systems (proprietary UEs, VPN connections) with a simpler network-based authentication mechanism. Instead of requiring complex device-level security implementations, the system uses network device verification of device identifiers and signature provision, substituting complex client-side mechanics with simpler network-side authentication

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If credentials are used for authentication, then ease of operation is improved, but security reliability deteriorates as credentials can be easily compromised

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses device identifiers as copies or representations of the UE's identity that are verified by the network device. Instead of relying on credentials that can be compromised, the system verifies authorized device identifiers and provides signatures that bind the authentication to specific devices. This approach maintains ease of operation while improving security reliability by eliminating credential-based authentication vulnerabilities

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9882894B2Secure authentication service
Publication Date: 2018.01.30 VERIZON PATENT & LICENSING INC
  • US9882894B2 patent drawing
  • US9882894B2 patent drawing
  • US9882894B2 patent drawing

AI summary

A first device may receive a request from a second device. The request may include a device identifier associated with the second device. The request may be transmitted by the second device to obtain a signature, based on which to access a third device. The first device may determine that the device identifier is associated with a secure authentication service. The first device may generate a signature based on determining that the device identifier is associated with the secure authentication service. The first device may provide the signature to the third device. The signature may permit the third device to selectively permit or deny access by the second device based on a result of authenticating the signature. Access may be permitted when the third device successfully authenticates the signature, and access may be denied when the third device fails to authenticate the signature.