Network Service Provider Authentication via Verification Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Providers of free content services face challenges in verifying the identity of content requesters due to limited or no out-of-band verification options, making it difficult to restrict access to appropriate content, such as preventing adults from accessing children's content or vice versa.

Innovation Solution

A network service provider-assisted authentication system that uses a verification server to compare user-provided identifying information against client data stored by the network service provider, employing a verification module to receive verification requests and respond based on client data, ensuring accurate identity verification without transmitting sensitive data across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If out-of-band verification mechanisms (such as payment processing systems) are used to verify identity, then identity verification reliability is improved, but service accessibility deteriorates because free services cannot require payment accounts

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a network service provider as an intermediary that possesses both client data and network address information. This intermediary enables identity verification by comparing user-provided identifying information against stored client data, while also providing the network address needed to contact the user. This resolves the contradiction by creating a verification path that doesn't require payment accounts, thus maintaining service accessibility while achieving reliable verification through the NSP's existing data holdings

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If no out-of-band verification is used to maintain service accessibility, then service accessibility is improved, but identity verification reliability deteriorates

Engineering Contradiction:
Improveservice accessibilityVSAvoididentity verification reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system leverages the network service provider's existing client data collection process. When users sign up for network services, they already provide identifying information that the NSP stores. This self-service approach means the verification infrastructure is built into the normal service provisioning process, maintaining accessibility while enabling verification through data that already exists in the NSP's databases

Inventive Principle:
Principle #25Self-service

3Reliability

If user-provided identifying information is transmitted across the network for verification, then identity verification capability is improved, but security deteriorates due to exposure of sensitive data

Engineering Contradiction:
Improveidentity verification capabilityVSAvoiddata security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential verification elements needed for identity confirmation. Instead of transmitting full user profiles or sensitive personal data, the system transmits only user-provided identifying information (such as name or address) and the network address. The actual verification comparison happens at the NSP, and only verification results are returned, minimizing data exposure while maintaining verification capability

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8880693B2Network service provider-assisted authentication
Publication Date: 2014.11.04 VERIZON PATENT & LICENSING INC
  • US8880693B2 patent drawing
  • US8880693B2 patent drawing
  • US8880693B2 patent drawing

AI summary

A data store includes previously collected client data records, each previously collected client data record associated with a respective first network address. A verification module is communicatively coupled to the data store, the module configured to determine that it is a competent verification module and to receive a verification request including user data and a second network address and further configured to respond with an indication of whether the user data corresponds to the previously collected client data record identified by the first network address corresponding to the second network address.