Single Secret Key for Multi-Provider Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in 3GPP cellular networks require multiple secret keys for user devices to access information from various sources, which can be resource-intensive and inefficient.

Innovation Solution

The system generates a single secret key using a key generator that can be shared among multiple information providers, allowing user devices to decrypt encrypted information from different sources without needing separate authentication processes for each provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple secret keys are used for authentication with different information providers, then security and authorization for each provider is maintained, but network resource consumption increases and authentication efficiency decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple secret keys into a single secret key that can be used for authentication with multiple information providers. The home subscriber server generates one secret key for the user device instead of requiring separate keys for each provider, reducing authentication overhead while maintaining security through the underlying GBA authentication framework

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single secret key generated by the home subscriber server serves multiple functions and can be used for authentication with different information providers. This universal key eliminates the need for provider-specific authentication processes, streamlining access to authorized content across multiple sources

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple secret keys are generated for different information providers, then access control for each provider is ensured, but device complexity and key management overhead increase

Engineering Contradiction:
Improveaccess controlVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functionality of multiple provider-specific secret keys into a single secret key managed by the user device. This consolidation simplifies key storage, retrieval, and management operations while the home subscriber server maintains the ability to control access to different information providers through the unified authentication mechanism

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate authentication processes are used for each information provider, then provider-specific authorization is maintained, but network resource consumption and processing time increase

Engineering Contradiction:
Improveauthorization accuracyVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The authentication process becomes universal and can be used with multiple information providers without modification. The single secret key enables the user device to authenticate with any authorized provider through the same process, eliminating redundant authentication operations and reducing network resource consumption while maintaining authorization accuracy

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8972729B2Secure information delivery
Publication Date: 2015.03.03 VERIZON PATENT & LICENSING INC
  • US8972729B2 patent drawing
  • US8972729B2 patent drawing
  • US8972729B2 patent drawing

AI summary

A first network device is configured to receive a request for content from a user device, determine that the user device is not authenticated, and send information to the user device that the user device requires authentication. The first network device is configured further to receive a notification that the user device is authorized to receive content from multiple content providers. The first network device is configured further to generate a secret key and authenticate the user device by using the secret key. The first network device is further configured to send the content to the user device.