Authentication Token Verification in Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods in mobile radio networks, such as UMTS, face challenges in efficiently and cost-effectively detecting errors or manipulations during the authentication process, particularly in identifying faults or deviations on the network side.
Innovation Solution
A method where a mobile terminal or USIM module receives an authentication vector containing a random number, sequence number, information parameter, and authentication code, and compares these with stored key values to generate expected responses, allowing for verification and transmission of response messages to authenticate access, while using encryption and data integrity values to assess authentication behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used in mobile networks, then authentication can be performed, but errors or manipulations during authentication cannot be efficiently detected
Solution Approach 1:
The patent applies preliminary action by having the mobile network pre-generate expected response messages and authentication tokens before the actual authentication process. The network stores these expected values and uses them to verify the mobile device's responses, enabling error detection without adding complex real-time verification mechanisms.
Solution Approach 2:
The patent implements feedback by comparing the mobile device's authentication responses against the pre-generated expected responses. This feedback mechanism allows the network to detect authentication errors or manipulations by identifying discrepancies between expected and actual responses, thereby improving authentication reliability.
2Reliability
If comprehensive authentication verification is implemented to detect errors and manipulations, then security is improved, but the complexity and cost of the authentication system increases
Solution Approach 1:
The patent applies self-service by enabling the mobile network to autonomously generate, store, and verify authentication tokens and expected responses without requiring external verification systems. The network's authentication center automatically performs all verification operations, simplifying implementation while maintaining security.
Solution Approach 2:
The patent uses copying by creating expected response messages that are copies or replicas of what the mobile device should generate. These expected responses are stored in the network and used for comparison, allowing verification without requiring the network to independently compute authentication values during the actual authentication process.
3Measurement precision
If authentication tokens with multiple components are used, then authentication accuracy is improved, but the complexity of processing and verifying authentication data increases
Solution Approach 1:
The patent applies segmentation by dividing the authentication token into multiple components: a sequence number, an authentication code, and other parameters. This segmentation allows the network to verify each component separately against corresponding expected values, improving verification accuracy while managing complexity through structured processing of individual elements.
Data Source
Figure 1
AI summary
The present invention relates to a method for checking authentication functions for authentication between a mobile radio network and a mobile terminal which can be operated in the mobile radio network and/or a mobile radio subscriber identification module (USIM) which allows a mobile terminal that can be operated in the mobile radio network to have authenticating access to the mobile radio network, wherein the mobile terminal and/or the mobile radio subscriber identification module (USIM) receives, in the course of the authentication, an authentication token comprising an authentication code (MAC), verifies the authentication token, generates an expected authentication code and compares it with the authentication code (MAC) from the authentication token and takes the result of the comparison as a basis for transmitting at least one response message to the mobile radio network, the at least one response message being produced using parameters which are managed in alterable form by the mobile terminal and/or by the mobile radio subscriber identification module (USIM) of the mobile terminal. The present invention also relates to a mobile terminal, a mobile radio subscriber identification module (USIM) and/or a mobile radio network which are respectively designed to carry out a method based on the invention.