Processor Bootstrapping Authorization for Automatic Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple username-password sets for various network services, leading to security issues and inconvenience, as they often need to remember or record multiple credentials, which can be compromised if one service is breached.

Innovation Solution

A processor in user equipment performs bootstrapping authorization with a remote operator to obtain and use a username and password for logging into a remote application server, composing and sending a log-in message automatically, thereby eliminating the need for manual input and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually input username and password for each network service, then authentication can be performed, but users face difficulties in managing multiple username-password sets leading to security issues and inconvenience

Engineering Contradiction:
Improveauthentication securityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where the system automatically obtains and manages credentials through a broker service. Instead of users directly managing multiple username-password sets, the intermediary service handles credential acquisition, storage, and submission automatically, resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service authentication where the user equipment automatically performs credential management without user intervention. The processor automatically obtains credentials from the broker service and uses them for authentication, eliminating the need for users to manually manage multiple credential sets while maintaining security through automated credential rotation and protection.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If users use a same username-password set for all network services, then ease of operation is improved, but security issues arise as personal information is exposed if one service is compromised

Engineering Contradiction:
Improvecredential managementVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication credentials by service, where each network service receives its own unique credential set automatically managed by the system. The broker service obtains separate credentials for different services, ensuring that compromise of one service does not expose credentials for other services, while users still experience ease of operation through automatic management.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If users write down or record username-password sets, then ease of operation is improved, but security issues such as peeking still exist

Engineering Contradiction:
Improvecredential accessVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical system of writing down or recording credentials with an automated electronic credential management system. The processor automatically obtains, stores, and submits credentials through cryptographic protocols, eliminating the need for physical or digital storage that users can access, thereby preventing peeking while maintaining ease of operation through automatic credential retrieval.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Ease of operation

If automatic authentication is implemented through bootstrapping, then security and ease of operation are improved, but device complexity increases due to additional processing steps

Engineering Contradiction:
Improveuser intervention requirementVSAvoidprocessing unit functionality
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication module in the processing unit that handles multiple authentication protocols and credential types through a single integrated system. This multi-functional approach allows the device to perform various authentication operations (obtaining credentials, composing authentication requests, submitting credentials) through a unified mechanism, reducing the impact of added complexity while achieving automatic secure authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10708267B2Method and associated processor for authentication
Publication Date: 2020.07.07 MEDIATEK INC
  • US10708267B2 patent drawing
  • US10708267B2 patent drawing
  • US10708267B2 patent drawing

AI summary

The present invention provides method and associated processor for authentication, e.g., log-in, with a remote application server by the processor of a user equipment, including: by the processor, achieving a bootstrapping authorization with a remote operator, obtaining a username and a password for logging in the remote application server according to the bootstrapping authorization, composing a log-in message according to the username and the password, and sending the log-in message to the remote application server.