Indirect Network Service Authentication Using Credential Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In certain wireless communications networks, authorization for a service is not supported indirectly, leading to challenges in authenticating network devices for accessing services.

Innovation Solution

A method and apparatus for network service authentication involve receiving credentials, determining their validity, and transmitting requests to authenticate network devices, using access tokens to facilitate indirect authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If indirect authorization is implemented for network services, then network device authentication capability is improved, but system complexity increases due to multiple credential verification steps

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediate network device that acts as a mediator between the second network device and the third network device. This intermediary verifies credentials and establishes authentication relationships, enabling indirect authorization while managing system complexity through a dedicated intermediary component rather than requiring all devices to perform complex verification themselves

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct verification steps: first credential verification between the first and second network devices, then second credential verification between the second and third network devices. This segmentation allows each authentication step to be handled independently, improving overall authentication capability while organizing system complexity into manageable segments

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple credentials are verified for indirect authentication, then security is improved, but authentication time increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The first credential verification between the first and second network devices is performed in advance before the actual service request is made. This preliminary authentication establishes a trusted relationship that can be leveraged for subsequent indirect authentication, improving security while reducing the time required during the actual service interaction

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous authentication context across multiple verification steps. The second network device uses its authenticated status with the first network device to facilitate verification with the third network device, creating a continuous chain of trust that improves security while minimizing redundant verification time

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS12495037B2Authentication for a network service
Publication Date: 2025.12.09 EDGEWOOD IP
  • US12495037B2 patent drawing
  • US12495037B2 patent drawing
  • US12495037B2 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for authentication for a network service. One method includes receiving, at a first network device from a second network device, a network function service request to execute a service on a third network device. The request includes first credentials for authentication with a first network device and second credentials for authentication with the third network device. The method includes determining whether the first credentials provided are valid and execute the service request by determining the third network device to execute the service requested from the second network device. The method includes transmitting, to a fourth network device, a request for authentication with the third network device. The request includes an identifier of the third network device and second credentials of the second network device.