Zero Sign-On Authentication Using Device-Stored Trust Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are burdened with multiple sign-on operations and password management across different online services, and there is a risk of identity theft due to widespread storage of credentials.

Innovation Solution

A zero sign-on system that leverages existing security infrastructure to authenticate users without requiring repeated password entries by using digital certificates or cookies stored on user devices, ensuring secure access to media services across trusted and untrusted networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users enter username and password at each business website, then authentication reliability is improved, but user convenience deteriorates due to multiple sign-on operations

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a third-party authentication service as an intermediary between users and multiple business websites. This authentication service acts as a mediator that verifies user credentials once and then issues authentication tokens that can be presented to multiple services, eliminating the need for repeated sign-on operations while maintaining security through centralized credential verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users store username and password combinations at multiple locations, then access flexibility is improved, but security deteriorates due to increased identity theft risk

Engineering Contradiction:
Improveaccess flexibilityVSAvoididentity theft risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication credentials from local storage at multiple user devices and consolidates them in a centralized authentication service. By removing credentials from multiple user-side storage locations, the system eliminates the security risk of credential theft while maintaining access flexibility through the centralized service that issues tokens to authorized devices

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The centralized authentication service serves as an intermediary that manages credential verification and token issuance. This mediator allows users to access multiple services without storing credentials locally, as the authentication service verifies credentials once and issues secure tokens that can be presented to multiple services without requiring credential storage at each location

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If digital certificates or cookies are stored on user devices, then authentication speed is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication speedVSAvoiddevice complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-storing authentication tokens and certificates on user devices during the initial authentication process. These pre-stored credentials enable rapid subsequent authentication without requiring repeated verification, significantly improving authentication speed. The system performs the complex verification work upfront during the initial sign-on, simplifying future authentication operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12407670B2Zero sign-on authentication
Publication Date: 2025.09.02 CABLE TELEVISION LAB INC
  • US12407670B2 patent drawing
  • US12407670B2 patent drawing
  • US12407670B2 patent drawing

AI summary

A method of facilitating zero sign-on access to media services depending on trust credentials. The trust credentials may be cookies, certificates, and other data sets operable to be stored on a device used to access the media services such that information included therein may be used to control the zero sign-on capabilities of the user device.