Proxy Authentication for Unauthenticated Personal Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual configuration of mobile devices for wireless network access is error-prone and inefficient, requiring significant human intervention and resulting in duplicate configurations when devices are upgraded or added for a single subscriber.

Innovation Solution

A system that allows an authenticated electronic device to proxy the registration, authentication, and configuration of unauthenticated devices, reducing human intervention by using the authenticated device to transmit identifiers and access information over a personal area network, thereby automating the network access and billing setup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration is used to provision mobile devices with network access information, then human intervention is required for device setup, but configuration errors and duplicate steps increase

Engineering Contradiction:
Improvedevice configuration processVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system enables devices to automatically provision themselves by detecting nearby authenticated devices and using them as proxies for authentication. The unauthenticated device initiates a discovery process, selects an appropriate proxy, and automatically completes registration without manual technician intervention, thereby eliminating configuration errors while maintaining ease of use

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authenticated devices serve as intermediaries or proxies between unauthenticated devices and the authentication server. These proxies handle the authentication requests on behalf of unauthenticated devices, enabling automatic configuration while maintaining security through the authenticated device's existing credentials

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If manual configuration is performed for each mobile device, then individual provisioning is achieved, but time consumption and resource waste increase

Engineering Contradiction:
Improveindividual device provisioningVSAvoidconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and provisioning actions for a primary device, then leverages those pre-completed actions to automatically configure additional devices. The discovery and selection of proxy devices occurs before the actual authentication, allowing bulk provisioning to benefit from the time saved in repeated manual configuration steps

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If authenticated devices proxy authentication requests, then server complexity is reduced, but device security exposure may increase

Engineering Contradiction:
Improveauthentication server complexityVSAvoidsecurity key exposure
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

Authenticated devices act as secure intermediaries that forward authentication requests to the server using their own established credentials. This intermediary approach allows the server to remain simpler while maintaining security, as the proxy devices handle the sensitive authentication logic and never expose their keys to unauthenticated devices or the server

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8561143B2Proxy registration and authentication for personal electronic devices
Publication Date: 2013.10.15 T MOBILE INNOVATIONS LLC
  • US8561143B2 patent drawing
  • US8561143B2 patent drawing
  • US8561143B2 patent drawing

AI summary

Communication systems, media, and methods for authenticating and registering unauthenticated electronic devices are provided. The communication systems include authorized electronic devices that proxy authentication and registration for one or more unauthenticated electronic devices. The unauthenticated electronic devices connect to the authenticated electronic device over a personal area network and initiate a communication session—via the authenticated electronic devices—with an authentication server located on a secure broadband wireless network that connects the one or more authenticated electronic devices. When the authentication server authorizes the unauthenticated electronic devices to access the secure broadband wireless network, network configuration data is communicated to the unauthenticated electronic devices via the authenticated electronic devices.