Registration Server Automatic Authentication Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current client-server systems require manual input of identifiers and secret values for authentication, which is inconvenient and prone to user error, and do not allow servers to automatically provision authentication data to client devices.

Innovation Solution

A registration server and gateway apparatus system that automatically generates and stores identifiers and secret values, using a token generation process to facilitate secure communication between devices and a connectivity server, enabling automatic authentication and data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual input of identifiers and secret values is required for authentication, then security can be maintained, but ease of operation deteriorates and user error increases

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system enables client devices to automatically obtain authentication credentials (identifier and secret value) without manual user input. The gateway apparatus automatically generates credentials and transmits them to client devices through the network, allowing the system to serve itself rather than requiring user intervention for authentication setup.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The gateway apparatus pre-generates and stores identifiers and secret values before client devices need to connect. This preliminary action of credential generation and storage eliminates the need for manual authentication setup at connection time, improving ease of operation while maintaining security through automated credential distribution.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automatic generation and storage of identifiers and secret values is implemented, then ease of operation improves, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The gateway apparatus serves as an intermediary component that handles the complex tasks of generating, storing, and distributing authentication credentials to client devices. By introducing this intermediary gateway, the complexity of automatic credential management is centralized rather than distributed to each client device, maintaining ease of operation while managing system complexity through a dedicated intermediary component.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If servers cannot reach clients automatically, then simplicity is maintained, but productivity deteriorates due to manual data fetching requirements

Engineering Contradiction:
ImproveproductivityVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system establishes client-device connections in advance before data transmission is needed. The gateway apparatus pre-authenticates client devices and maintains connection state, enabling the server to automatically push data to clients when new data becomes available, thereby improving productivity through automated data delivery without requiring complex real-time connection establishment mechanisms.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9154487B2Registration server, gateway apparatus and method for providing a secret value to devices
Publication Date: 2015.10.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9154487B2 patent drawing
  • US9154487B2 patent drawing
  • US9154487B2 patent drawing

AI summary

The present invention relates to auto-provisioning of authentication data for client devices. A registration server includes a gateway determination unit, which is configured to determine a gateway apparatus transferring a request signal from a device, and a processing unit. The processing unit is configured to transmit a first signal including a token and first access information of the gateway apparatus to the device if an identifier of the gateway apparatus is stored on the server, and to transmit a second signal indicating a positive response to the gateway apparatus when it obtains the token and the identifier based on a third signal received in response to the first signal. The gateway apparatus sends the secret value to the device when it receives the second signal.