Two-Phase IP Network Login via Mobile OTP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in managing multiple passwords for various services, and existing access methods are vulnerable to abuse, complex for operators, and require significant infrastructure changes, especially in public Wi-Fi networks where static usernames can be easily copied and access servers may interfere with existing radio networks.
Innovation Solution
A two-phase login process using a one-time password (OTP) transferred via mobile telecommunications, where the first phase authenticates the OTP and the second phase creates a temporary account with unique credentials, allowing access to an IP network without upgrading existing access servers, and enabling uniform login across different Wireless Internet Service Providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static username and password are used for login, then user can access IP network, but username can be easily copied and used by several persons
Solution Approach 1:
The system performs preliminary authentication actions by sending OTP to mobile device before granting network access. The OTP is generated and delivered in advance as part of the login process, ensuring that only authenticated users can access the network while maintaining a simple interface for users.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using mobile phones as a mediator between the user and the network. The mobile device receives and verifies OTP codes, acting as a secure intermediary that prevents direct credential sharing while maintaining user-friendly access.
2Reliability
If one-time password (OTP) is used to prevent copying, then access security is improved, but login procedure becomes more complex
Solution Approach 1:
The system implements self-service authentication where the user's own mobile device automatically receives and processes the OTP. The authentication server generates and sends the OTP to the user's mobile number, and the user simply enters the received code without needing to understand or manage complex security protocols.
Solution Approach 2:
The patent makes the authentication system universal by using mobile phones, which most users already possess and are familiar with. The same mobile device serves multiple functions: receiving OTP, verifying credentials, and providing network access authorization, eliminating the need for separate security tokens or complex authentication hardware.
3Reliability
If access server is upgraded to support secure login, then access security is improved, but existing access servers cannot be reused
Solution Approach 1:
The patent introduces an intermediary authentication server that handles the secure OTP generation and verification, working in conjunction with existing access servers. This intermediary layer provides enhanced security without requiring modifications to the existing access server infrastructure, allowing organizations to reuse their current network equipment.
Solution Approach 2:
The authentication system is segmented into separate functional components: the existing access server handles network connectivity, while a new authentication server handles OTP generation and verification. This segmentation allows the access server to remain unchanged while security is enhanced through the separate authentication module.
4Ease of operation
If uniform login interface is implemented across different WISPs, then user experience is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal login interface that works across different WISPs by using the common mobile phone platform. The authentication mechanism is designed to be provider-agnostic, allowing users to log in to any participating WISP using the same OTP-based process through their mobile device, creating a unified user experience.
Solution Approach 2:
The system dynamically adapts to different WISP environments while maintaining a uniform interface. The authentication server can dynamically generate OTPs and communicate with various access servers through standardized protocols, allowing the system to flexibly support multiple providers without requiring separate interfaces for each.
Data Source
AI summary
The present invention relates to an arrangement and a method respectively for providing an end user with access to an IP network (login). It comprises a user station, an access server of an access network, a web server and an authentication server. The end user station comprises first means for communication with the access server and second means for communication over a mobile telecommunication system with the authentication server. The access/login procedure comprises a first and a second phase, the authentication server controls the first phase comprising a one-time-password (OTP) login sequence, and, if the one time password (OTP) is valid, the second login phase is performed in order to login the end user at the access server, by creating a temporary account for which user credentials are defined.


