Zero Sign-On Authentication via Gateway Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of user devices accessing media services through various devices within a home poses security challenges for service providers, as traditional sign-on based authentication processes burden both user devices and service providers, especially when dealing with less secure devices operating on non-proprietary systems with multiple communication mediums.

Innovation Solution

Implementing a zero sign-on authentication process that relies on the level of trust associated with gateways rather than user devices, where access is predicated on the trustworthiness of the gateway, eliminating the need for user devices to provide certificates or input passwords, and shifting authentication processing to gateways, which track and assess the trustworthiness based on MAC addresses, domain names, SNMP communications, and BPI+ certification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sign-on based authentication processes are implemented to address security concerns, then security is improved, but processing burden on user devices and service providers increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway as an intermediary device between user devices and media service providers. The gateway performs authentication and certificate management functions, acting as a mediator that reduces the processing burden on both user devices and service providers while maintaining security. The gateway stores and manages certificates locally, eliminating the need for user devices to handle complex authentication processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication and certificate management functions from user devices and relocates them to a dedicated gateway device. This separation removes the security processing burden from user devices, allowing them to simply connect through the gateway without needing to store or process certificates directly.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If certificates are assigned to each user device for authentication, then security is improved, but device complexity and memory requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate storage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the certificate storage and management function into the gateway device, which serves multiple users and devices. Instead of each user device having its own certificate storage, the gateway consolidates certificate management for all devices in the home, reducing overall system complexity and memory requirements across individual devices.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If manual sign-on with username and password is required, then security is improved, but ease of operation decreases

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automatic authentication where the gateway automatically performs certificate-based authentication with the media service provider without requiring user intervention. The system serves itself by automatically establishing secure connections, eliminating the need for users to manually enter credentials while maintaining strong security through certificate-based authentication.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If security applications operate on user devices, then authentication capability is improved, but processing burden on user devices increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprocessing burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway acts as an intermediary that provides authentication capabilities to user devices without requiring the devices themselves to run complex security applications. The gateway handles all cryptographic operations and certificate management, allowing user devices to remain simple while still benefiting from robust authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8793769B2Zero sign-on authentication
Publication Date: 2014.07.29 CABLE TELEVISION LAB INC
  • US8793769B2 patent drawing
  • US8793769B2 patent drawing
  • US8793769B2 patent drawing

AI summary

A authenticating system and process for authenticating user devices to a access a media service where access to certain portions of the media service may be limited according to a gateway or other device used by a user device to facilitate interfacing a user with the media service. The authentication may be achieved without directly assessing a trustworthiness of the user devices, and optionally, without requiring a user thereof to complete a sign-on operation.