Mobile Authentication Message Location Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in mobile devices are vulnerable to man-in-the-middle attacks, where attackers can access networks by mimicking legitimate connections, leading to potential misuse and damage, as existing solutions like KR 20100054191 and US 2008/182592 do not effectively prevent such attacks, especially when the attacker is in a different service network.

Innovation Solution

A method that verifies the authenticity of authentication messages by using location information associated with radio access nodes, where the mobile device generates and transmits a list of location information to the network, allowing the network to check if the origin of the authentication request is valid by matching the first location information with the list, thereby preventing man-in-the-middle attacks without requiring modifications to the HLR/AuC or (U)SIM.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (UMTS AKA) are used, then authentication between mobile device and network is established, but the system is vulnerable to man-in-the-middle attacks where attackers can access networks by mimicking legitimate connections

Engineering Contradiction:
Improveauthentication securityVSAvoidman-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a new dimension for authentication verification by incorporating location information (cell ID, tracking area code, location area code) into the authentication process. This spatial dimension complements the traditional cryptographic authentication, creating a multi-dimensional verification system that prevents man-in-the-middle attacks by ensuring the authentication request originates from the expected location.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent uses location information as an intermediary element to verify the authenticity of authentication requests. The network entity compares the location information received with expected location data, acting as a mediator to detect and prevent unauthorized access attempts without modifying the core authentication protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If location information verification is added to authentication messages, then protection against man-in-the-middle attacks is enhanced, but the complexity of the authentication procedure increases

Engineering Contradiction:
Improveman-in-the-middle attacksVSAvoidauthentication procedure complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent leverages the existing multi-functionality of authentication messages by embedding location information within the same message structures already used for cryptographic authentication. This approach allows the system to perform both traditional authentication and location verification using the same communication channel, avoiding the need for separate verification procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent modifies existing authentication parameters by adding location information fields to authentication messages. Rather than introducing entirely new verification protocols, the solution changes the parameters of existing messages to include spatial data, thereby enhancing security while maintaining compatibility with current authentication frameworks.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If location information is transmitted in authentication messages, then authenticity verification is improved, but the amount of data transmitted increases

Engineering Contradiction:
Improveauthenticity verificationVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential location identification elements (cell ID, tracking area code, location area code) from complete location data sets. By transmitting only these critical identifiers rather than full location information, the system achieves effective authenticity verification while minimizing the additional data burden on communication channels.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2395780B1Authenticity verification of authentication messages
Publication Date: 2019.08.07 KONINK KPN NV
  • EP2395780B1 patent drawingFigure 1
  • EP2395780B1 patent drawingFigure 2
  • EP2395780B1 patent drawingFigure 3

AI summary

At least a method for verifying the authenticity of one or more authentication messages in an authentication procedure between a network and a mobile device is described wherein the method comprises: sending an authentication request through a first radio access node to a said mobile device, said radio access node being associated with first location information; said mobile device generating second location information associated with the location of said mobile device; and, verifying the authenticity of the origin of said authentication request by checking if said second location information comprises said first location information.