Zero Sign-On Authentication via Gateway Trust Levels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of user devices accessing media services through various platforms, such as satellite, broadcast, and cable television, poses security challenges for service providers, as they need to secure devices with non-proprietary operating systems and multiple communication mediums, leading to increased processing burdens and the need for sign-on based authentication processes.

Innovation Solution

Implementing a zero sign-on authentication system that relies on the level of trust associated with gateways rather than user devices, where access is granted based on the trustworthiness of the gateway, eliminating the need for users to input passwords or provide certificates, and reducing security processing demands on both user devices and service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sign-on based authentication processes are implemented to address security concerns, then security is improved, but processing burden on user devices and service providers increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication decision-making function from user devices and relocates it to the service provider's server. The server determines whether a user device is authorized to access media services without requiring the device to perform complex authentication processing, thereby reducing the processing burden on user devices while maintaining security through centralized authentication logic

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the service provider's server acts as a mediator between the user device and media services. Instead of direct authentication between user devices and services, the server intermediates by receiving access requests, determining authorization based on service subscription information, and granting or denying access accordingly

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If certificates are assigned to each user device for authentication, then security is improved, but device complexity and processing burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes the requirement for user devices to store, manage, and transmit authentication certificates. Instead, the server maintains authentication information and makes authorization decisions centrally, eliminating the need for certificate processing at the user device level while preserving security through server-side authentication validation

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If manual sign-on with username and password is required, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automatic authentication where the system itself performs the authorization determination without requiring user intervention. When a user device requests access to media services, the server automatically checks subscription information and grants or denies access without requiring the user to manually sign on with username and password, thereby maintaining security while significantly improving ease of operation

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11962826B2Zero sign-on authentication
Publication Date: 2024.04.16 CABLE TELEVISION LAB INC
  • US11962826B2 patent drawing
  • US11962826B2 patent drawing
  • US11962826B2 patent drawing

AI summary

An authenticating system and process for authenticating user devices to a access a service where access to certain portions of the service may be limited according to a access point or other device used by a user device to facilitate interfacing a user with the service. The authentication may be achieved without directly assessing a trustworthiness of the user devices, and optionally, without requiring a user thereof to complete a sign-on operation.