Mobile Device Authentication via Secondary Short-Range Channel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication systems face security risks due to ease of eavesdropping, allowing adversaries to intercept authentication data and gain unauthorized access, particularly during device pairing processes in protocols like Bluetooth, Wi-Fi, and 1xEVDO.

Innovation Solution

Implementing a secondary short-range authentication channel, such as RFID or optical bar codes, that requires physical proximity for data exchange, making it difficult for adversaries to intercept authentication data without detection, and using an authentication algorithm to verify trusted devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If authentication data is transmitted over wireless channels during device pairing, then device connectivity and communication capability are improved, but security risk increases due to ease of eavesdropping

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication channel that mediates the pairing process. Instead of directly exchanging authentication data over the primary wireless channel (which is vulnerable to eavesdropping), the system uses a secondary authentication channel to securely exchange authentication data first, then uses that data to establish the primary communication channel. This intermediary step protects the vulnerable pairing process while maintaining connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into distinct phases using separate communication channels. The authentication data exchange occurs over a dedicated secondary channel (such as NFC, Bluetooth Low Energy, or visual confirmation), separate from the primary data communication channel. This segmentation isolates the vulnerable authentication phase from the main communication flow, reducing the attack surface while maintaining overall system connectivity.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If a secondary short-range authentication channel is implemented requiring physical proximity, then security is improved by preventing eavesdropping, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent leverages existing multi-functional components in mobile devices to implement the secondary authentication channel. For example, the device's display and camera (used for visual authentication), or the NFC antenna (used for close-proximity wireless authentication), serve dual purposes: their primary functions plus authentication. This approach enhances security without significantly increasing device complexity, as the same hardware components perform multiple roles.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication mechanism utilizes resources already present in the device itself rather than requiring external dedicated hardware. The device uses its own display to show authentication codes, its camera to capture visual verification, or its existing short-range wireless capabilities for authentication. This self-service approach maintains security while minimizing additional complexity, as the device leverages its own existing capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3223488B1Method for secure authentication of mobile devices
Publication Date: 2023.06.07 NOKIA OF AMERICA CORP
  • EP3223488B1 patent drawingFigure 1~2
  • EP3223488B1 patent drawingFigure 3
  • EP3223488B1 patent drawingFigure 4~5

AI summary

A method for authenticating a mobile device is provided. The method includes receiving a communication request from the mobile device. The mobile device is operable to exchange data over a primary channel. Authentication data is received from the mobile device over a second channel. The secondary channel is a short-range channel operable for exchanging data when the mobile device is within physical proximity. The authentication data is processed to determine whether the mobile device is a trusted device.