Untrusted Device Cellular Access via Trusted Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Untrusted devices, such as voice-enabled digital assistants, lack secure access to cellular network services due to their inability to participate directly in the network and the challenge of authenticating individual users in multi-user environments, leading to potential unauthorized access to private information.

Innovation Solution

Implementing a method for untrusted devices to authenticate through OAuth 2.0 or similar protocols, using a trusted device's credentials to establish trust, and employing session management to ensure secure access while managing multiple user interactions, including abbreviated authentication for efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If untrusted devices are allowed to access cellular network services, then service accessibility is improved, but security and authorization control deteriorate

Engineering Contradiction:
Improveservice accessibilityVSAvoidsecurity and authorization control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trusted device as an intermediary between the untrusted device and the cellular network. The trusted device holds the actual credentials and acts as a mediator that authorizes the untrusted device to access network services. This resolves the contradiction by enabling service accessibility through the untrusted device while maintaining security control through the trusted device intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication and access control functions into two separate components: the trusted device that holds credentials and provides authorization, and the untrusted device that provides service accessibility. This segmentation allows each component to specialize in its strength - the trusted device ensures security while the untrusted device enables broad access.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If multiple users share an untrusted device, then ease of operation is improved, but authentication complexity and security risk increase

Engineering Contradiction:
Improvemulti-user accessVSAvoidauthentication complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where each user can independently authenticate themselves through the trusted device associated with their cellular account. The system automatically manages the authentication process without requiring manual configuration or complex setup, allowing multiple users to easily access the untrusted device while maintaining individual security controls.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The trusted device serves as an intermediary that simplifies multi-user authentication. Instead of requiring complex authentication protocols on the untrusted device, each user simply uses their trusted device to prove their identity, and the trusted device mediates the authentication with the network, reducing overall complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If voice commands are used for authentication, then ease of operation is improved, but susceptibility to unauthorized access in public environments worsens

Engineering Contradiction:
Improvevoice command authenticationVSAvoidunauthorized access in public environments
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent merges multiple authentication factors - voice recognition, device identification from the trusted device, and network authorization - into a comprehensive authentication system. This combination maintains the ease of voice command operation while layering additional security measures that prevent unauthorized access in public environments by requiring multiple verification elements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The trusted device acts as an intermediary that verifies the authenticity of voice commands and other authentication inputs. Even if voice commands are intercepted or spoofed in public environments, the trusted device's involvement as a mediator ensures that only authorized users can successfully authenticate, combining ease of operation with enhanced security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10555172B2Untrusted device access to services over a cellular network
Publication Date: 2020.02.04 T MOBILE US INC
  • US10555172B2 patent drawing
  • US10555172B2 patent drawing
  • US10555172B2 patent drawing

AI summary

Cellular networks regularly operate with trusted devices, which typically are trusted because of the integration of a SIM card therewith. Untrusted devices typically do not interface with a SIM card, and rely on user input through traditional user interfaces for authentication. Recently, the use of hands-free, always-on digital assistant devices have become more common. Such devices typically have only a voice user interface that may be used by a number of people in close proximity to the device. Particular problems arise in such a scenario when a user wants to access a secure service that requires user authentication. Such problems are addressed with multiple techniques described herein.