User Premises Device Authentication via Credentials Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional user authentication methods, such as usernames and passwords, are cumbersome and vulnerable to personal denial of service (PDoS) attacks, which can lock users out of online systems, disrupting access to essential services.

Innovation Solution

A user premises device, capable of monitoring and controlling physical security networks, is used to input credentials like fingerprints or voice prints, which are verified by an authentication server to grant access to online systems, providing an additional security layer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional username and password authentication is used, then users can access online systems, but security is compromised and users face PDoS attacks that lock them out

Engineering Contradiction:
Improveauthentication securityVSAvoidPDoS attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a credentials service as an intermediary component between the user's client device and the online system. This service hosts credentials (biometric data, behavioral patterns, device identifiers) on a separate server, allowing authentication without exposing sensitive data to the online system or making it vulnerable to PDoS attacks. The credentials service acts as a mediator that verifies authentication requests and provides access tokens, thereby enhancing security while protecting against denial of service attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple usernames and passwords are required for different online services, then access to various services is enabled, but user burden increases and authentication becomes cumbersome

Engineering Contradiction:
Improveaccess to multiple servicesVSAvoidauthentication convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The credentials service is designed to store and manage multiple types of credentials (biometric data, behavioral patterns, device identifiers) that can be used across different online systems. Instead of requiring users to remember separate usernames and passwords for each service, the system uses a universal credential verification mechanism that works across multiple platforms. The credentials service can authenticate users based on various credential types and provide appropriate access tokens, simplifying the authentication process while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If usernames and passwords are stored locally, then authentication can be performed, but security risks increase from data breaches and unauthorized access

Engineering Contradiction:
Improveauthentication functionalityVSAvoiddata breach risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts sensitive credential data from local storage on client devices and relocates it to a secure credentials service hosted on a separate server. Instead of storing biometric data, passwords, or other sensitive authentication information locally where they are vulnerable to breaches, the system extracts these credentials and stores them in a dedicated secure service. The client device only stores non-sensitive identifiers, while the actual credential verification occurs remotely, significantly reducing the risk of data breaches and unauthorized access.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10356096B2Authentication using credentials submitted via a user premises device
Publication Date: 2019.07.16 AT&T INTELLECTUAL PROPERTY I L P
  • US10356096B2 patent drawing
  • US10356096B2 patent drawing
  • US10356096B2 patent drawing

AI summary

An authentication system can be operable to receive from a user premises device credentials associated with a user identity, wherein the user premises device can also be operable to monitor and control a premise of the user identity. The authentication system can process the credentials and transmit an authentication verification to an on-line system to enable access to the on-line system by a user equipment of the user identity. The authentication system can be used as a factor (or additional factor) of authentication, for example, to gain sooner access to an on-line system that has locked out a user identity in response to a personal denial of service (PDoS) attack.