Carrier-Validated MFA Using Device Attestation Against SIM Spoofing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SMS-based multi-factor authentication (MFA) systems are vulnerable to interception, spoofing, replay attacks, and lack device-level verification, failing to meet regulatory security standards and excluding users without mobile phones, with usability challenges and high susceptibility to phishing.
Innovation Solution
A multi-factor authentication framework using cryptographic techniques and device-level validations, involving a cloud-based MFA service that verifies device authenticity through attested blobs, mutual authentication with carrier networks, and post-quantum cryptography to ensure secure and scalable access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If SMS-based MFA is used for authentication, then ease of operation is improved, but reliability deteriorates due to interception and spoofing vulnerabilities
Solution Approach 1:
The patent replaces the SMS-based mechanical communication system with a cryptographic authentication system using end-to-end encrypted channels. The authentication mechanism transitions from relying on vulnerable SMS protocols to using modern cryptographic primitives including key pairs, signed blobs, and encrypted communication channels, thereby maintaining ease of operation while dramatically improving reliability
Solution Approach 2:
The patent changes the fundamental parameters of the authentication system by transitioning from unencrypted SMS messages to encrypted communication channels with end-to-end security. It introduces new parameters such as cryptographic key pairs, signed authentication blobs, and encrypted session tokens, thereby transforming the system from vulnerable to secure while maintaining operational simplicity
2Reliability
If device validation mechanisms are added to verify device authenticity, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent implements self-service device validation where the device autonomously generates cryptographic key pairs, creates signed authentication blobs, and manages its own authentication credentials without requiring complex external validation infrastructure. The device serves itself by performing cryptographic operations locally, thereby improving reliability while minimizing the added complexity
3Reliability
If carrier network integration is implemented for mutual authentication, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent introduces an encrypted communication channel as an intermediary between the device and carrier network. This intermediary layer handles the complexity of mutual authentication, key exchange, and session management, allowing the device to achieve high reliability through carrier integration without directly bearing the full complexity burden. The intermediary abstracts and manages the complex authentication protocols
Data Source
AI summary
The invention provides systems, methods, and computer-readable media for multi-factor authentication (MFA) using device and carrier validation. A user device generates an attested blob containing cryptographic keys and a Universal Integrated Circuit Card (UICC)-originated International Mobile Subscriber Identity (IMSI), which is transmitted to a cloud-based MFA service. The service validates the attested blob, coordinates with an Original Equipment Manufacturer (OEM) service, and executes an Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA) process with the carrier network to establish mutual trust. Authentication data, including a validated phone number independent of the device's stored number, is securely stored in a cloud wallet. The invention enhances security by mitigating risks such as spoofing, replay attacks, and SIM swapping, providing a novel authentication framework compatible with modern networks.


