Automatic Mobile Device Authentication via Network Identifier Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional user authentication methods for mobile devices, such as username and password challenges, pose security risks and user inconvenience due to the need for manual input on limited keypads, and fail to ensure device authorization and data plan validation.

Innovation Solution

Implementing an automatic device authentication and account identification mechanism that retrieves and encrypts a mobile device's unique identifiers (MTN and MEID) and verifies them through the network's AAA system, eliminating the need for user input and ensuring device authorization without exposing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional username and password authentication is used on mobile devices, then user identification can be achieved, but security risks increase and user convenience decreases due to manual input requirements on limited keypads

Engineering Contradiction:
Improveauthentication securityVSAvoiduser input convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device automatically performs authentication using pre-stored credentials and device identifiers without requiring user input. The system retrieves the user's phone number and device identifier, encrypts them, and sends them to the server for automatic verification, eliminating the need for manual username and password entry.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical keyboard input system with an automatic electronic authentication system. Instead of requiring physical keystrokes on a limited mobile keypad, the system uses automated retrieval of device identifiers and cryptographic operations to perform authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual authentication input is required on mobile devices, then user identification can be verified, but authentication time increases and user experience deteriorates

Engineering Contradiction:
Improveaccount verification accuracyVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication准备工作 in advance by pre-storing the user's phone number and device identifier in secure memory. When authentication is needed, these credentials are immediately retrieved and processed without requiring user input or waiting for manual entry.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If device authentication is not automatically performed, then network security may be compromised, but implementation complexity increases requiring additional authentication steps

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses the mobile device's existing phone number (MTN) as both a communication identifier and an authentication credential. This multi-functional approach leverages an already-universal identifier for authentication purposes, eliminating the need for separate usernames and passwords while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9106665B2Automatic device authentication and account identification without user input when application is started on mobile station
Publication Date: 2015.08.11 CELLCO PARTNERSHIP INC
  • US9106665B2 patent drawing
  • US9106665B2 patent drawing
  • US9106665B2 patent drawing

AI summary

Disclosed procedures automatically identify a carrier-authorized mobile station and verify an account related identifier associated with the device, in response to start-up of an application in the device. Application start-up causes the device to send a request to an application server, with the device's current IP address, MTN and a device identifier such as MEID or ESN. The server queries an AAA system of the network to retrieve the MTN that has been assigned the IP address. If the retrieved MTN matches the MTN passed to the server in the request, the server queries a network database such as DMD for the device identifier associated with the MTN. A match of the device identifier retrieved from the network database with that passed to the server via the request indicates authenticity of the requesting device and its MTN.