Untrusted Device Cellular Access via Trusted Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Untrusted devices, such as voice-enabled digital assistants, lack secure access to cellular network services due to their inability to participate directly in the network and the challenge of authenticating individual users in multi-user environments, leading to potential unauthorized access to private information.
Innovation Solution
Implementing a method for untrusted devices to authenticate through OAuth 2.0 or similar protocols, using a trusted device's credentials to establish trust, and employing session management to ensure secure access while managing multiple user interactions, including abbreviated authentication for efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If untrusted devices are allowed to access cellular network services, then service accessibility is improved, but security and authorization control deteriorate
Solution Approach 1:
The patent introduces a trusted device as an intermediary between the untrusted device and the cellular network. The trusted device holds the actual credentials and acts as a mediator that authorizes the untrusted device to access network services. This resolves the contradiction by enabling service accessibility through the untrusted device while maintaining security control through the trusted device intermediary.
Solution Approach 2:
The patent segments the authentication and access control functions into two separate components: the trusted device that holds credentials and provides authorization, and the untrusted device that provides service accessibility. This segmentation allows each component to specialize in its strength - the trusted device ensures security while the untrusted device enables broad access.
2Ease of operation
If multiple users share an untrusted device, then ease of operation is improved, but authentication complexity and security risk increase
Solution Approach 1:
The patent implements self-service authentication where each user can independently authenticate themselves through the trusted device associated with their cellular account. The system automatically manages the authentication process without requiring manual configuration or complex setup, allowing multiple users to easily access the untrusted device while maintaining individual security controls.
Solution Approach 2:
The trusted device serves as an intermediary that simplifies multi-user authentication. Instead of requiring complex authentication protocols on the untrusted device, each user simply uses their trusted device to prove their identity, and the trusted device mediates the authentication with the network, reducing overall complexity.
3Ease of operation
If voice commands are used for authentication, then ease of operation is improved, but susceptibility to unauthorized access in public environments worsens
Solution Approach 1:
The patent merges multiple authentication factors - voice recognition, device identification from the trusted device, and network authorization - into a comprehensive authentication system. This combination maintains the ease of voice command operation while layering additional security measures that prevent unauthorized access in public environments by requiring multiple verification elements.
Solution Approach 2:
The trusted device acts as an intermediary that verifies the authenticity of voice commands and other authentication inputs. Even if voice commands are intercepted or spoofed in public environments, the trusted device's involvement as a mediator ensures that only authorized users can successfully authenticate, combining ease of operation with enhanced security.
Data Source
AI summary
Cellular networks regularly operate with trusted devices, which typically are trusted because of the integration of a SIM card therewith. Untrusted devices typically do not interface with a SIM card, and rely on user input through traditional user interfaces for authentication. Recently, the use of hands-free, always-on digital assistant devices have become more common. Such devices typically have only a voice user interface that may be used by a number of people in close proximity to the device. Particular problems arise in such a scenario when a user wants to access a secure service that requires user authentication. Such problems are addressed with multiple techniques described herein.


