Set-Top Box Single Sign-On via Intermediary Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of set-top boxes must currently undergo separate registration and authentication processes for each service provider to access different applications, requiring repeated input of sensitive information and establishing unnecessary relationships with service providers for temporary usage.

Innovation Solution

A method where a set-top box registers with a single registration and authentication provider, allowing users to authenticate once and share necessary data, while keeping user information anonymous, using Liberty Alliance Protocols and digital rights management systems like Verimatrix Content Authority System for secure and efficient access to multiple service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate registration and authentication processes are used for each service provider, then access control and security are maintained for each provider, but users must repeatedly input sensitive information and undergo multiple authentication processes

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a set-top box as an intermediary device that centralizes authentication credentials and automatically manages authentication across multiple service providers. The set-top box stores authentication information securely and presents it to service providers as needed, eliminating the need for users to manually input credentials repeatedly while maintaining security through controlled access management

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines multiple authentication processes into a single unified authentication event. By implementing single sign-on functionality, the system allows users to authenticate once with a service provider and automatically gain access to other authorized services without repeating the authentication process, thereby simplifying operations while maintaining security through centralized credential management

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If users register with each service provider individually, then service providers can verify user identities and manage authorizations, but users must establish relationships with multiple providers even for temporary usage

Engineering Contradiction:
Improveuser identity verificationVSAvoidregistration system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The set-top box is designed as a universal authentication device that can interact with multiple different service providers through a standardized interface. It maintains a centralized user profile that can be presented to various service providers, allowing the same device to fulfill authentication requirements across different services without requiring separate registration processes for each provider

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The set-top box acts as a mediator between users and multiple service providers, managing all authentication and authorization relationships centrally. It verifies user identities once and then handles communications with various service providers on behalf of the user, reducing the complexity of individual registrations while maintaining reliable identity verification through centralized management

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If authentication information is stored locally at user workstations, then single-sign-on can be implemented, but security risks increase from local storage of sensitive data

Engineering Contradiction:
Improvesingle-sign-on capabilityVSAvoidsecurity risk from local storage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The set-top box serves as a secure intermediary device that centralizes the storage of authentication information in a controlled environment rather than at分散 user workstations. It manages credentials securely using dedicated security mechanisms and only presents authentication data when required by authorized service providers, maintaining single-sign-on functionality while reducing security risks through centralized secure storage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of storing credentials locally on user devices with an electronic centralized management system. The set-top box uses electronic credential management with secure storage mechanisms and controlled access protocols, substituting the vulnerable local file storage approach with a more secure electronic authentication management infrastructure

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8756624B2Method for single sign-on when using a set-top box
Publication Date: 2014.06.17 BEIJING XIAOMI MOBILE SOFTWARE CO LTD
  • US8756624B2 patent drawing
  • US8756624B2 patent drawing
  • US8756624B2 patent drawing

AI summary

When the set-top box (STB) has been switched on, registration and authentication with the provider (IDP) are carried out (1, 2, 3). Following successful authentication, a piece of authentication information is then sent (4) to the set-top box (STB), which the set-top box (STB) sends (5) to a service provider (SP1) for registration. The service provider (SP1) then sets up (6) a connection to the provider (IDP) of the registration and authentication function in order to verify the authentication information and to request guidelines for charging, and the provider (IDP) of the registration and authentication function sends (7) confirmation to the service provider.