Cardless Terminal Authentication via Key Generation Center

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for cardless terminals in telecommunication networks lack a scheme to generate a key between the terminal and a service server, making it difficult to ensure secure data transmission.

Innovation Solution

An authentication method and system that involves an Application Server (AS) generating a key generation request containing a user ID and AS ID, which is transmitted to an authentication server or gateway equipment, resulting in a key being generated and used for authentication between the cardless terminal and the service server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cardless terminal uses SIP Digest authentication with password input, then authentication can be performed, but there is no scheme to generate a key between the terminal and service server for secure data transmission

Engineering Contradiction:
Improveauthentication capabilityVSAvoidkey generation scheme
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key generation center (KGC) as an intermediary entity that mediates key generation between the cardless terminal and service server. The KGC receives key generation requests from the terminal, generates cryptographic keys using the user's password and identity information, and distributes the keys to both the terminal and service server, enabling secure authentication without requiring complex local key generation capabilities at the terminal

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cardless terminal performs self-service authentication by inputting the user's password and identity information, which are then used by the KGC to generate authentication keys. The terminal itself can initiate key generation requests and participate in the authentication process without requiring a physical SIM card or additional hardware security modules

Inventive Principle:
Principle #25Self-service

2Reliability

If a card terminal uses SIM/USIM/ISIM with preset Ki/K for key generation, then secure authentication is achieved, but cardless terminals lack such a scheme

Engineering Contradiction:
Improvedata transmission securityVSAvoidterminal operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a functional copy of the SIM card authentication mechanism for cardless terminals. Instead of relying on physical SIM cards with embedded cryptographic elements, the system uses software-based authentication where the user's password and identity information serve as the cryptographic foundation, replicated through the KGC to generate equivalent security keys

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/physical SIM card system with an electronic/software-based authentication system. The physical SIM card containing cryptographic keys is substituted with a software authentication mechanism using password-based key generation, eliminating the need for physical hardware while maintaining security through cryptographic equivalence

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2521304B1Authentication method, system and apparatus
Publication Date: 2019.11.27 CHINA MOBILE COMM GRP CO LTD
  • EP2521304B1 patent drawingFigure 1
  • EP2521304B1 patent drawingFigure 2
  • EP2521304B1 patent drawingFigure 3

AI summary

The present invention provides an authentication method, system and apparatus. The method comprises the steps of: receiving, by an application server (AS), an AS access request containing a user ID from a user equipment (UE); generating, by the AS, a key generation request according to the user ID and transmitting the request to a network side; and receiving, by the AS, a key from the network side and authenticating the UE according to the key. In this invention, a key is generated between a cardless terminal and an AS, and the generated key is then used to perform authentication between the AS and a UE, thereby security of data transmission can be improved.