Secure Application Data Usage Accounting via Authentication Packages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for data usage accounting on computing devices with both secure and personal applications fail to accurately segregate data usage between enterprise and personal data, leading to difficulties in determining the percentage of data consumption attributable to secure applications.

Innovation Solution

A method and system for authenticating computing devices that involves sending an authentication package uniquely associated with the device to an authentication server, enabling secure data exchange and accounting, with the option to buffer data from secure applications during authentication, and using profiles to exclude certain applications from accounting and prioritize network locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If data usage accounting is performed on a device with both secure and personal applications, then data consumption can be tracked, but it becomes difficult to accurately segregate and determine the percentage of data usage attributable specifically to secure applications

Engineering Contradiction:
Improvedata usage measurement accuracyVSAvoidaccounting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments data usage accounting by creating separate accounting mechanisms for secure applications versus personal applications. It introduces distinct data sessions, authentication packages, and accounting records that specifically track data consumption by secure applications, enabling precise measurement without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication server and authentication package mechanism that mediates between the device and data networks. This intermediary enables selective tracking of secure application data usage by verifying authentication credentials and routing accounting information appropriately, thus improving measurement precision without proportionally increasing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If authentication packages are sent for each data session request to enable accurate accounting, then data usage can be tracked, but the authentication process adds time and complexity to data exchange operations

Engineering Contradiction:
Improvedata usage tracking accuracyVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication by sending authentication packages before actual data sessions are established. This allows the system to pre-verify credentials and set up accounting parameters in advance, so that during actual data exchange, tracking can proceed without repeated authentication delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous authentication states and session records that persist across multiple data requests. Once authenticated, the device maintains active accounting sessions that continue tracking data usage without requiring re-authentication for each subsequent request, thereby reducing time loss while maintaining tracking accuracy.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If data from secure applications is buffered during authentication, then accurate accounting can be ensured, but data transmission delay increases

Engineering Contradiction:
Improveaccounting reliabilityVSAvoiddata transmission speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent implements buffering as a cushioning mechanism that temporarily stores data during authentication transitions. This cushioning approach ensures that no data is lost during authentication states while maintaining accounting reliability, as buffered data is subsequently transmitted and accounted for once authentication is complete.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent dynamically adjusts buffering behavior based on authentication state and data session context. Rather than buffering all data uniformly, the system selectively buffers only when necessary for accounting reliability, and dynamically releases buffered data when authentication is complete, thus minimizing transmission delays while maintaining reliability.

Inventive Principle:
Principle #15Dynamics

4Ease of operation

If transparent authentication is implemented for secure applications, then ease of operation is improved, but the complexity of the authentication system increases

Engineering Contradiction:
Improveuser operation simplicityVSAvoidauthentication system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the device automatically generates, sends, and manages authentication packages without requiring user intervention. The system autonomously handles credential verification, session establishment, and accounting configuration, making operation transparent and simple for users while concentrating complexity within the automated authentication subsystem.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses an intermediary authentication server that handles the complex verification and accounting logic externally. This mediator absorbs much of the authentication system complexity on the server side, allowing the client device to maintain simplicity and transparency for end users while still implementing robust authentication and tracking capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9100390B1Method and system for enrolling and authenticating computing devices for data usage accounting
Publication Date: 2015.08.04 OMNISSA LLC
  • US9100390B1 patent drawing
  • US9100390B1 patent drawing
  • US9100390B1 patent drawing

AI summary

A method and system for authenticating a computing device for data usage accounting are described herein. As an example, the method can be practiced on a computing device that includes secure applications and unsecure applications. A data session request for a secure application can be received, and in response to the data session request, a data session connection can be initiated. As part of initiating the data session connection, an authentication package uniquely associated with the computing device can be sent to the authentication server. If the computing device is authenticated, the data session connection can be established to enable data exchange and data accounting in which the authenticating may be performed exclusively for the secure applications.