Mobile Authentication Message Location Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods in mobile devices are vulnerable to man-in-the-middle attacks, where attackers can access networks by mimicking legitimate connections, leading to potential misuse and damage, as existing solutions like KR 20100054191 and US 2008/182592 do not effectively prevent such attacks, especially when the attacker is in a different service network.
Innovation Solution
A method that verifies the authenticity of authentication messages by using location information associated with radio access nodes, where the mobile device generates and transmits a list of location information to the network, allowing the network to check if the origin of the authentication request is valid by matching the first location information with the list, thereby preventing man-in-the-middle attacks without requiring modifications to the HLR/AuC or (U)SIM.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (UMTS AKA) are used, then authentication between mobile device and network is established, but the system is vulnerable to man-in-the-middle attacks where attackers can access networks by mimicking legitimate connections
Solution Approach 1:
The patent introduces a new dimension for authentication verification by incorporating location information (cell ID, tracking area code, location area code) into the authentication process. This spatial dimension complements the traditional cryptographic authentication, creating a multi-dimensional verification system that prevents man-in-the-middle attacks by ensuring the authentication request originates from the expected location.
Solution Approach 2:
The patent uses location information as an intermediary element to verify the authenticity of authentication requests. The network entity compares the location information received with expected location data, acting as a mediator to detect and prevent unauthorized access attempts without modifying the core authentication protocol.
2Object-affected harmful factors
If location information verification is added to authentication messages, then protection against man-in-the-middle attacks is enhanced, but the complexity of the authentication procedure increases
Solution Approach 1:
The patent leverages the existing multi-functionality of authentication messages by embedding location information within the same message structures already used for cryptographic authentication. This approach allows the system to perform both traditional authentication and location verification using the same communication channel, avoiding the need for separate verification procedures.
Solution Approach 2:
The patent modifies existing authentication parameters by adding location information fields to authentication messages. Rather than introducing entirely new verification protocols, the solution changes the parameters of existing messages to include spatial data, thereby enhancing security while maintaining compatibility with current authentication frameworks.
3Reliability
If location information is transmitted in authentication messages, then authenticity verification is improved, but the amount of data transmitted increases
Solution Approach 1:
The patent extracts only the essential location identification elements (cell ID, tracking area code, location area code) from complete location data sets. By transmitting only these critical identifiers rather than full location information, the system achieves effective authenticity verification while minimizing the additional data burden on communication channels.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
At least a method for verifying the authenticity of one or more authentication messages in an authentication procedure between a network and a mobile device is described wherein the method comprises: sending an authentication request through a first radio access node to a said mobile device, said radio access node being associated with first location information; said mobile device generating second location information associated with the location of said mobile device; and, verifying the authenticity of the origin of said authentication request by checking if said second location information comprises said first location information.