Operator Switch Consent Token via Challenge-Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for operator switch in machine-to-machine (M2M) devices lack efficient mechanisms to ensure user consent across different service providers, leading to cumbersome processes, potential denial of service, and trust issues between operators, especially when dealing with large populations of inexpensive devices that cannot handle complex cryptographic protocols.

Innovation Solution

A method involving a user consent token creation process, where an authenticating server challenges the user to provide consent using a second device, verifying the response, and issuing a token that records user consent for a switch from one service provider to another, utilizing cryptographic means and involving a subscription manager or third-party authentication to ensure trust and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication protocols (PEAP, EAP-FAST, SAML, Kerberos) are used for operator switch, then user and device authentication is provided, but the process becomes complex, time-consuming, and requires trusted third parties that neither operator can act as

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the consent verification function from complex authentication protocols and implements it as a simple challenge-response mechanism. The authenticating server sends a challenge to the user's device, which responds with consent information, eliminating the need for complex protocols like PEAP, EAP-FAST, SAML, or Kerberos while maintaining authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authenticating server as an intermediary that facilitates consent verification between operators and users. This server manages the challenge-response process and token issuance, eliminating the need for operators to directly trust each other or implement complex mutual authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If device-subscriber binding is not implemented, then device credentials alone can be used for authentication, but malicious subscribers can provide consent to one operator while causing denial of service for another operator's device

Engineering Contradiction:
Improveauthentication simplicityVSAvoiddenial of service risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary device-subscriber binding verification before allowing operator switch. The authenticating server checks whether the device is bound to the subscriber before processing the consent challenge, preventing malicious subscribers from causing denial of service to other operators' devices while maintaining simple authentication flow.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If TLS or SSL stacks are required for authentication, then secure communication is achieved, but weaker M2M devices cannot handle the processor-heavy requirements

Engineering Contradiction:
Improvecommunication securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces heavy cryptographic protocols with a lightweight challenge-response mechanism that uses minimal processing resources. Instead of requiring M2M devices to handle processor-intensive TLS/SSL stacks, the system uses simple challenge messages and response tokens that can be processed by weaker devices while maintaining communication security through the authenticating server's verification process.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Reliability

If operators independently verify user consent, then both operators can trust the consent process, but multiple authentication rounds and symmetric key establishment are required

Engineering Contradiction:
Improveconsent verification trustVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the consent verification process into a single authentication flow where the authenticating server handles both operator trust verification and consent validation in one process. Instead of requiring multiple separate authentication rounds and symmetric key establishment, the system combines these functions into a unified challenge-response mechanism that reduces time while maintaining trust.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9027101B2Providing subscriber consent in an operator exchange
Publication Date: 2015.05.05 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US9027101B2 patent drawing
  • US9027101B2 patent drawing
  • US9027101B2 patent drawing

AI summary

A method and system for providing a record of consent in scenarios in which the user and a device may have to perform a function that involves two entities that don't trust each other or are not necessary interested in cooperating. In one such example, a user wants to switch services from an “old” operator to a “new” operator. An operator switch without explicit user consent may have legal or business ramifications for both the “old” and “new” operators. The ramifications are even more severe if the switch is the result of actions of, for example, a hacker maliciously causing this switches in order to cause monetary or other damage to either operators or denial of service to the users. In such cases it is useful for both operators to be on record and have an archive of proof of user consent should future disputes arise.