Mobile Network Authentication via Inter-Device Sequence Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile network systems face security challenges in authenticating message originators and processing financial transactions due to vulnerabilities in EAP-TLS, which require pre-requisite user credentials and third-party encryption, limiting adoption and growth, especially in areas lacking developed infrastructure, and are susceptible to man-in-the-middle attacks and fraudulent transactions.
Innovation Solution
A method and system for secure identification of message originators in mobile networks using secure inter-device communication protocols like NFC, Bluetooth, and IR, where devices exchange identifiers and requests are processed by a server based on the sequence and time difference of receiving messages, ensuring authentication and authorization without relying solely on higher-level server security, thus reducing the risk of spoofing and fraud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP-TLS with pre-requisite user credentials and third-party encryption is used, then security is improved, but device complexity and infrastructure requirements increase
Solution Approach 1:
The patent extracts the security verification function from the server and relocates it to the client device. The device autonomously verifies the server's authenticity using locally stored credentials (device fingerprint, certificate authority public key) without requiring third-party encryption infrastructure or complex server-side authentication mechanisms.
Solution Approach 2:
The device performs self-authentication and server verification using its own credentials and stored authentication data. The system enables devices to independently verify server identity and establish secure connections without relying on external authentication servers or complex infrastructure.
2Reliability
If EAP-TLS with mutual authentication is required, then security against man-in-the-middle attacks is improved, but ease of operation deteriorates
Solution Approach 1:
The patent extracts the authentication burden from the connection process and places it in the device before connection establishment. The device pre-stores authentication credentials (device fingerprint, certificate authority public key) and uses them automatically during connection, eliminating the need for users to manually configure mutual authentication.
Solution Approach 2:
The device performs authentication preparation in advance by storing credentials (device fingerprint, certificate authority public key) locally before connection is needed. This preliminary setup enables automatic verification during connection establishment without requiring user action or complex real-time authentication procedures.
3Reliability
If centralized authentication systems are used, then security control is improved, but vulnerability to sniffing and replay attacks worsens
Solution Approach 1:
The patent segments the authentication system into distributed client-based verification units. Each device independently verifies server authenticity using locally stored credentials rather than relying on a centralized authentication system. This segmentation prevents centralized points of failure and reduces vulnerability to sniffing and replay attacks.
Solution Approach 2:
The device's locally stored credentials (device fingerprint, certificate authority public key) act as intermediaries for security verification. Instead of centralized authentication, the device uses these intermediary credentials to independently verify server identity and establish secure connections without transmitting sensitive authentication data.
4Reliability
If pre-requisite user credentials are required, then authentication security is improved, but network growth and adoption are limited
Solution Approach 1:
The device performs self-authentication using credentials it already possesses (device fingerprint, stored certificate authority public key). New devices can autonomously authenticate to the network without requiring pre-provisioned user credentials or manual enrollment processes, enabling rapid network growth and adoption.
Solution Approach 2:
The patent extracts the authentication credential requirement from the network enrollment process. Devices use locally stored credentials (device fingerprint, certificate authority public key) for authentication without needing pre-requisite user credentials from the network administrator, simplifying onboarding and enabling network expansion.
Data Source
AI summary
Technologies are generally described for methods and systems effective to secure process synchronized requests after at least one secure inter-device communication link between the originating and confirming communication devices is established. A method may include forwarding, by the confirming communication device the request and receiving, by a server, a first request from the originating device and at least one second request from the confirming device. The method may also include, by the server, determining a sequence of receiving of the first and the at least one second requests and processing the requests in order to authenticate a communication device, accept or reject a financial transaction, based on the receiving sequence and receiving time difference.


