Service Controller Beacon Broadcast for Secure Client Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in seamlessly and securely connecting client devices to service controllers, particularly in environments where manual input of access credentials is required, leading to inefficiencies and potential security vulnerabilities.

Innovation Solution

A system and method that utilize a service controller to broadcast connection information and an access credential hash, allowing client devices to connect securely by matching the hash with an access credential communicated through out-of-band channels, such as visual or audio signals, enabling automated discovery and connection without direct user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual input of access credentials is required for connection, then security can be maintained through user control, but connection efficiency and ease of operation deteriorate due to manual intervention

Engineering Contradiction:
ImprovesecurityVSAvoidconnection efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-establishing trust relationships between devices before actual connection is needed. The first device generates and stores authentication credentials in advance, and the second device obtains these credentials through out-of-band communication channels before the actual connection process, eliminating the need for manual credential input during connection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary out-of-band communication channel that mediates the transfer of authentication credentials between devices. This intermediary channel (such as display-screen communication or audio communication) allows secure credential transfer without requiring direct network connection or manual user input, thus maintaining security while improving connection efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access credentials are transmitted through standard communication channels, then connection process is simplified, but security deteriorates due to potential interception

Engineering Contradiction:
Improveconnection processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transitions credential transmission from the standard network communication dimension to an out-of-band communication dimension. By using display-screen communication or audio communication channels that are separate from the network protocol stack, the system creates a secure credential transfer path that is independent of potentially compromised network channels.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The out-of-band communication channel acts as an intermediary that separates the credential transfer process from the main network communication path. This intermediary mechanism allows credentials to be exchanged through a different, more secure channel while the actual service connection can proceed through standard channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated discovery and connection is implemented, then productivity and efficiency improve, but device complexity increases due to additional components

Engineering Contradiction:
Improveconnection automationVSAvoidsystem components
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements multi-functional components that can operate in multiple modes. The communication module can handle both out-of-band credential exchange and standard network communication, while the processor can manage both credential verification and service connection processes. This universality reduces the need for separate dedicated components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the credential management and connection establishment processes into a unified automated workflow. The first device combines credential generation, storage, and transmission functions, while the second device combines credential reception, verification, and connection initiation functions, reducing overall system complexity through functional integration.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3266179B1Discovery and connection to a service controller
Publication Date: 2019.12.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3266179B1 patent drawingFigure 1
  • EP3266179B1 patent drawingFigure 2
  • EP3266179B1 patent drawingFigure 3

AI summary

The claimed subject matter includes techniques for discovering to and connecting to a service controller. The claimed subject matter may disclose a processor and a memory of a service controller to store connection information, an access credential, and an access credential hash. A beacon broadcaster to broadcast the connection information and the access credential hash to a client device, may also be disclosed. The present disclosure may also include an access credential director to send the access credential to an out-of-band communicator. The present disclosure may also include a client connector to receive a connection request from the client device and allow access to a client device based on the client device's use of the connection information.