Secure Application Data Usage Accounting via Authentication Packages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for data usage accounting on computing devices with both secure and personal applications fail to accurately segregate data usage between enterprise and personal data, leading to difficulties in determining the percentage of data consumption attributable to secure applications.
Innovation Solution
A method and system for authenticating computing devices that involves sending an authentication package uniquely associated with the device to an authentication server, enabling secure data exchange and accounting, with the option to buffer data from secure applications during authentication, and using profiles to exclude certain applications from accounting and prioritize network locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If data usage accounting is performed on a device with both secure and personal applications, then data consumption can be tracked, but it becomes difficult to accurately segregate and determine the percentage of data usage attributable specifically to secure applications
Solution Approach 1:
The patent segments data usage accounting by creating separate accounting mechanisms for secure applications versus personal applications. It introduces distinct data sessions, authentication packages, and accounting records that specifically track data consumption by secure applications, enabling precise measurement without requiring complete system redesign.
Solution Approach 2:
The patent introduces an intermediary authentication server and authentication package mechanism that mediates between the device and data networks. This intermediary enables selective tracking of secure application data usage by verifying authentication credentials and routing accounting information appropriately, thus improving measurement precision without proportionally increasing complexity.
2Measurement precision
If authentication packages are sent for each data session request to enable accurate accounting, then data usage can be tracked, but the authentication process adds time and complexity to data exchange operations
Solution Approach 1:
The patent implements preliminary authentication by sending authentication packages before actual data sessions are established. This allows the system to pre-verify credentials and set up accounting parameters in advance, so that during actual data exchange, tracking can proceed without repeated authentication delays.
Solution Approach 2:
The patent maintains continuous authentication states and session records that persist across multiple data requests. Once authenticated, the device maintains active accounting sessions that continue tracking data usage without requiring re-authentication for each subsequent request, thereby reducing time loss while maintaining tracking accuracy.
3Reliability
If data from secure applications is buffered during authentication, then accurate accounting can be ensured, but data transmission delay increases
Solution Approach 1:
The patent implements buffering as a cushioning mechanism that temporarily stores data during authentication transitions. This cushioning approach ensures that no data is lost during authentication states while maintaining accounting reliability, as buffered data is subsequently transmitted and accounted for once authentication is complete.
Solution Approach 2:
The patent dynamically adjusts buffering behavior based on authentication state and data session context. Rather than buffering all data uniformly, the system selectively buffers only when necessary for accounting reliability, and dynamically releases buffered data when authentication is complete, thus minimizing transmission delays while maintaining reliability.
4Ease of operation
If transparent authentication is implemented for secure applications, then ease of operation is improved, but the complexity of the authentication system increases
Solution Approach 1:
The patent implements self-service authentication where the device automatically generates, sends, and manages authentication packages without requiring user intervention. The system autonomously handles credential verification, session establishment, and accounting configuration, making operation transparent and simple for users while concentrating complexity within the automated authentication subsystem.
Solution Approach 2:
The patent uses an intermediary authentication server that handles the complex verification and accounting logic externally. This mediator absorbs much of the authentication system complexity on the server side, allowing the client device to maintain simplicity and transparency for end users while still implementing robust authentication and tracking capabilities.
Data Source
AI summary
A method and system for authenticating a computing device for data usage accounting are described herein. As an example, the method can be practiced on a computing device that includes secure applications and unsecure applications. A data session request for a secure application can be received, and in response to the data session request, a data session connection can be initiated. As part of initiating the data session connection, an authentication package uniquely associated with the computing device can be sent to the authentication server. If the computing device is authenticated, the data session connection can be established to enable data exchange and data accounting in which the authenticating may be performed exclusively for the secure applications.


