Two-Phase IP Network Login via Mobile OTP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in managing multiple passwords for various services, and existing access methods are vulnerable to abuse, complex for operators, and require significant infrastructure changes, especially in public Wi-Fi networks where static usernames can be easily copied and access servers may interfere with existing radio networks.

Innovation Solution

A two-phase login process using a one-time password (OTP) transferred via mobile telecommunications, where the first phase authenticates the OTP and the second phase creates a temporary account with unique credentials, allowing access to an IP network without upgrading existing access servers, and enabling uniform login across different Wireless Internet Service Providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static username and password are used for login, then user can access IP network, but username can be easily copied and used by several persons

Engineering Contradiction:
Improvelogin simplicityVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication actions by sending OTP to mobile device before granting network access. The OTP is generated and delivered in advance as part of the login process, ensuring that only authenticated users can access the network while maintaining a simple interface for users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using mobile phones as a mediator between the user and the network. The mobile device receives and verifies OTP codes, acting as a secure intermediary that prevents direct credential sharing while maintaining user-friendly access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If one-time password (OTP) is used to prevent copying, then access security is improved, but login procedure becomes more complex

Engineering Contradiction:
Improveaccess securityVSAvoidlogin procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service authentication where the user's own mobile device automatically receives and processes the OTP. The authentication server generates and sends the OTP to the user's mobile number, and the user simply enters the received code without needing to understand or manage complex security protocols.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes the authentication system universal by using mobile phones, which most users already possess and are familiar with. The same mobile device serves multiple functions: receiving OTP, verifying credentials, and providing network access authorization, eliminating the need for separate security tokens or complex authentication hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access server is upgraded to support secure login, then access security is improved, but existing access servers cannot be reused

Engineering Contradiction:
Improveaccess securityVSAvoidinfrastructure cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent introduces an intermediary authentication server that handles the secure OTP generation and verification, working in conjunction with existing access servers. This intermediary layer provides enhanced security without requiring modifications to the existing access server infrastructure, allowing organizations to reuse their current network equipment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into separate functional components: the existing access server handles network connectivity, while a new authentication server handles OTP generation and verification. This segmentation allows the access server to remain unchanged while security is enhanced through the separate authentication module.

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If uniform login interface is implemented across different WISPs, then user experience is improved, but system complexity increases

Engineering Contradiction:
Improvelogin interface uniformityVSAvoidsystem integration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal login interface that works across different WISPs by using the common mobile phone platform. The authentication mechanism is designed to be provider-agnostic, allowing users to log in to any participating WISP using the same OTP-based process through their mobile device, creating a unified user experience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adapts to different WISP environments while maintaining a uniform interface. The authentication server can dynamically generate OTPs and communicate with various access servers through standardized protocols, allowing the system to flexibly support multiple providers without requiring separate interfaces for each.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8108903B2Arrangement and a method relating to IP network access
Publication Date: 2012.01.31 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US8108903B2 patent drawing
  • US8108903B2 patent drawing
  • US8108903B2 patent drawing

AI summary

The present invention relates to an arrangement and a method respectively for providing an end user with access to an IP network (login). It comprises a user station, an access server of an access network, a web server and an authentication server. The end user station comprises first means for communication with the access server and second means for communication over a mobile telecommunication system with the authentication server. The access/login procedure comprises a first and a second phase, the authentication server controls the first phase comprising a one-time-password (OTP) login sequence, and, if the one time password (OTP) is valid, the second login phase is performed in order to login the end user at the access server, by creating a temporary account for which user credentials are defined.