Trusted Home Device Intermediary for Client Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital authentication methods for devices and users over digital networks face challenges in efficiently and securely identifying unique devices, particularly when third-party developers lack access to internal digital credentials, limiting reliable authentication for access to networked services.
Innovation Solution
An automated digital authentication process where a client device generates a digital secret, which is transmitted to a trusted home device and then securely forwarded to a security server, allowing the home device to vouch for the client device, enabling secure authentication by leveraging the trust established between the home device and the security server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manufacturers burn in digital credentials to device hardware or firmware, then device identification reliability is improved, but access to these credentials is severely restricted preventing third-party developers from using them
Solution Approach 1:
The patent introduces a trusted home device as an intermediary that bridges the gap between the security server and client devices. The trusted device receives secrets from the security server and shares them with client devices through secure local communication, enabling third-party developers to authenticate devices without direct access to manufacturer credentials.
2Adaptability or versatility
If trusted home devices share secrets with security servers over wide area networks, then authentication capability is improved, but vulnerability to network interception is increased
Solution Approach 1:
The patent segments the authentication process into two distinct communication phases: (1) secure local area network transmission between client device and trusted home device, and (2) wide area network transmission between trusted home device and security server. This segmentation isolates the vulnerable WATP communication to only the necessary secret forwarding, while local communications remain secure through proximity-based trust.
3Productivity
If client devices use automated authentication processes, then authentication efficiency is improved, but complexity of the authentication system increases
Solution Approach 1:
The patent implements self-service mechanisms where client devices automatically generate authentication secrets and trusted home devices automatically forward them to the security server without manual user intervention. The system performs automated secret generation, transmission, and verification, reducing user burden while managing complexity through automated protocols.
Data Source
AI summary
Applications executing on phones, tablets and other client devices can be designed to authenticate with network services, but reliably identifying a client device that is not previously known to the service can be difficult. A television receiver or other trusted device that is previously known to the service, however, can act as an intermediary for initially delivering the client's identifying data to the authentication service. After the authentication service has received reliable identifying information about the client from another trusted device, the service is able to directly authenticate the client device in subsequent transactions by requesting and verifying receipt of the same secret identifier.

