Mobile Network Operator Authentication Phishing Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems, including those using hardware tokens like Mobile Connect, remain vulnerable to phishing attacks, leading to security issues where users may inadvertently authenticate with fake websites, compromising their accounts.

Innovation Solution

A mobile network operator system that verifies the authenticity of authentication requests by sending a second authentication request to the user's device, ensuring that both the initiating and second authentication responses come from the same device, thereby detecting potential phishing attempts and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware token is used for authentication, then authentication reliability is improved, but vulnerability to phishing attacks remains

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidphishing attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a mobile network operator system as an intermediary between the service provider and the user's authentication device. This intermediary verifies authentication requests by checking whether the user's mobile device is present and active, thereby preventing phishing attacks where attackers impersonate service providers. The intermediary adds an additional verification layer that confirms the legitimacy of the authentication context.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension to authentication by verifying not only the credentials but also the presence and state of the user's mobile device through the mobile network operator. This dimensional addition checks whether the device is currently active and reachable via mobile network, creating a spatial-temporal verification layer that phishing attacks cannot easily replicate.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If traditional authentication methods are used, then ease of operation is maintained, but security against phishing attacks deteriorates

Engineering Contradiction:
Improveauthentication easeVSAvoidphishing attack risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system leverages the user's existing mobile device and mobile network connection for verification purposes. The mobile network operator automatically checks whether the user's mobile device is active and reachable, without requiring additional user actions beyond the standard authentication process. This self-service approach maintains ease of operation while enhancing security.

Inventive Principle:
Principle #25Self-service

3Difficulty of detecting and measuring

If mobile network operator verification is implemented, then phishing detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvephishing detection capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The mobile network operator system performs multiple functions: it authenticates the user's identity, verifies the presence of the mobile device, checks the device's active state, and prevents phishing attacks. By consolidating these verification functions into a single multi-functional system, the patent reduces overall system complexity while improving phishing detection capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3582469B1Authentication using a mobile network operator system
Publication Date: 2021.07.07 KONINK KPN NV
  • EP3582469B1 patent drawingFigure 1a~1b
  • EP3582469B1 patent drawingFigure 2a
  • EP3582469B1 patent drawingFigure 2b

AI summary

Some embodiments are directed to a mobile network operator system (MNO system; 200). The MNO system is configured to - receive an initiating authentication request from the consumption device over the computer network, the initiating authentication request comprising the mobile network identifier, - send a first authentication request to the authentication device with the mobile network identifier and receive a first authentication response from the authentication device in response, - send a second authentication request to the authentication device with the mobile network identifier and receive a second authentication response from the consumption device in response, - verify the first authentication response and the second authentication response and verify that the second authentication response and the initiating authentication request were received from the same consumption device, - send an authentication success message.