Authentication Token Verification in Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods in mobile radio networks, such as UMTS, face challenges in efficiently and cost-effectively detecting errors or manipulations during the authentication process, particularly in identifying faults or deviations on the network side.

Innovation Solution

A method where a mobile terminal or USIM module receives an authentication vector containing a random number, sequence number, information parameter, and authentication code, and compares these with stored key values to generate expected responses, allowing for verification and transmission of response messages to authenticate access, while using encryption and data integrity values to assess authentication behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in mobile networks, then authentication can be performed, but errors or manipulations during authentication cannot be efficiently detected

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication verification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the mobile network pre-generate expected response messages and authentication tokens before the actual authentication process. The network stores these expected values and uses them to verify the mobile device's responses, enabling error detection without adding complex real-time verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by comparing the mobile device's authentication responses against the pre-generated expected responses. This feedback mechanism allows the network to detect authentication errors or manipulations by identifying discrepancies between expected and actual responses, thereby improving authentication reliability.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive authentication verification is implemented to detect errors and manipulations, then security is improved, but the complexity and cost of the authentication system increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem implementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies self-service by enabling the mobile network to autonomously generate, store, and verify authentication tokens and expected responses without requiring external verification systems. The network's authentication center automatically performs all verification operations, simplifying implementation while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses copying by creating expected response messages that are copies or replicas of what the mobile device should generate. These expected responses are stored in the network and used for comparison, allowing verification without requiring the network to independently compute authentication values during the actual authentication process.

Inventive Principle:
Principle #26Copying

3Measurement precision

If authentication tokens with multiple components are used, then authentication accuracy is improved, but the complexity of processing and verifying authentication data increases

Engineering Contradiction:
Improveauthentication verification accuracyVSAvoidauthentication processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the authentication token into multiple components: a sequence number, an authentication code, and other parameters. This segmentation allows the network to verify each component separately against corresponding expected values, improving verification accuracy while managing complexity through structured processing of individual elements.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2103080B1Checking of authentication functions
Publication Date: 2020.02.12 VODAFONE HOLDING GMBH
  • EP2103080B1 patent drawingFigure 1

AI summary

The present invention relates to a method for checking authentication functions for authentication between a mobile radio network and a mobile terminal which can be operated in the mobile radio network and/or a mobile radio subscriber identification module (USIM) which allows a mobile terminal that can be operated in the mobile radio network to have authenticating access to the mobile radio network, wherein the mobile terminal and/or the mobile radio subscriber identification module (USIM) receives, in the course of the authentication, an authentication token comprising an authentication code (MAC), verifies the authentication token, generates an expected authentication code and compares it with the authentication code (MAC) from the authentication token and takes the result of the comparison as a basis for transmitting at least one response message to the mobile radio network, the at least one response message being produced using parameters which are managed in alterable form by the mobile terminal and/or by the mobile radio subscriber identification module (USIM) of the mobile terminal. The present invention also relates to a mobile terminal, a mobile radio subscriber identification module (USIM) and/or a mobile radio network which are respectively designed to carry out a method based on the invention.