Mobile Device Authentication via Network Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional password authentication methods are insecure due to weak passwords and vulnerability to replay attacks, making them ineffective for reliable user authentication in service access.
Innovation Solution
A method and system that utilize a mobile device's registration with a communication network to authenticate users by transferring a device identifier, which is then used to encrypt and verify a user identifier, ensuring secure access to services without requiring direct password entry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If password authentication is used, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent introduces a service provider as an intermediary that mediates between the user and the service. The service provider receives authentication requests, verifies device identifiers, and forwards authentication assertions to services. This intermediary approach maintains ease of operation for users while improving security by adding a verification layer that prevents direct password exposure and replay attacks.
Solution Approach 2:
The patent creates a copy of the authentication process through the service provider. Instead of directly authenticating with services, the user's authentication is copied and verified by the service provider first. The service provider obtains device identifiers, verifies them against registered information, and then provides authentication assertions to services. This copying mechanism maintains operational simplicity while enhancing security through additional verification.
2Reliability
If alternative authentication methods (physical token, biometric) are used, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent enables the mobile device to perform self-service authentication using its existing device identifier (such as device ID or IMEI) that is already registered with the service provider. The device automatically provides this identifier when requesting service, and the service provider verifies it without requiring additional hardware or complex user actions. This approach achieves enhanced security using the device's own existing resources rather than requiring external authentication hardware.
Solution Approach 2:
The patent makes the device identifier serve multiple functions: it identifies the device to the network, authenticates the user to services, and provides a unique identifier for security verification. By making the device identifier universal across these different functions, the patent eliminates the need for separate authentication hardware while maintaining security. The same identifier used for network access also serves as the authentication credential.
3Reliability
If device identifier authentication is implemented, then authentication security is improved, but ease of operation is worsened
Solution Approach 1:
The patent performs preliminary authentication actions by the service provider before the user accesses the service. The service provider first obtains and verifies the device identifier against registered information, then provides an authentication assertion to the service. This preliminary verification happens automatically in the background without requiring the user to understand or interact with the authentication mechanism, maintaining ease of operation while ensuring security.
Solution Approach 2:
The patent implements a feedback mechanism where the service provider verifies the device identifier and provides authentication feedback to both the user and the service. The service provider receives the device identifier, compares it against registered information, and provides appropriate feedback (authentication success or failure). This automated feedback loop ensures security verification while keeping the user experience simple, as the user only needs to request service and receives automatic authentication feedback.
Data Source
AI summary
An identification system comprises a communication interface. The communication interface is configured to receive from a mobile device a registration request to initiate an access session between the mobile device and a communication network, wherein the registration request comprises a device identifier that identifies the mobile device. In response to the registration request, the communication interface is configured to transfer a packet address to the mobile device, wherein the mobile device transfers a service request for a service on the communication network during the access session, wherein the service request includes the packet address. The communication interface is configured to receive an identification request transferred from an authentication system in response to the service request, wherein the identification request indicates the packet address. In response to the identification request, the communication interface is configured to transfer the device identifier for delivery to the authentication system to authenticate the mobile device for the service using the device identifier.


