Mobile Network Authentication via Inter-Device Sequence Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile network systems face security challenges in authenticating message originators and processing financial transactions due to vulnerabilities in EAP-TLS, which require pre-requisite user credentials and third-party encryption, limiting adoption and growth, especially in areas lacking developed infrastructure, and are susceptible to man-in-the-middle attacks and fraudulent transactions.

Innovation Solution

A method and system for secure identification of message originators in mobile networks using secure inter-device communication protocols like NFC, Bluetooth, and IR, where devices exchange identifiers and requests are processed by a server based on the sequence and time difference of receiving messages, ensuring authentication and authorization without relying solely on higher-level server security, thus reducing the risk of spoofing and fraud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAP-TLS with pre-requisite user credentials and third-party encryption is used, then security is improved, but device complexity and infrastructure requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security verification function from the server and relocates it to the client device. The device autonomously verifies the server's authenticity using locally stored credentials (device fingerprint, certificate authority public key) without requiring third-party encryption infrastructure or complex server-side authentication mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The device performs self-authentication and server verification using its own credentials and stored authentication data. The system enables devices to independently verify server identity and establish secure connections without relying on external authentication servers or complex infrastructure.

Inventive Principle:
Principle #25Self-service

2Reliability

If EAP-TLS with mutual authentication is required, then security against man-in-the-middle attacks is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity against attacksVSAvoidadoption ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication burden from the connection process and places it in the device before connection establishment. The device pre-stores authentication credentials (device fingerprint, certificate authority public key) and uses them automatically during connection, eliminating the need for users to manually configure mutual authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The device performs authentication preparation in advance by storing credentials (device fingerprint, certificate authority public key) locally before connection is needed. This preliminary setup enables automatic verification during connection establishment without requiring user action or complex real-time authentication procedures.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized authentication systems are used, then security control is improved, but vulnerability to sniffing and replay attacks worsens

Engineering Contradiction:
Improvesecurity controlVSAvoidsniffing and replay attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into distributed client-based verification units. Each device independently verifies server authenticity using locally stored credentials rather than relying on a centralized authentication system. This segmentation prevents centralized points of failure and reduces vulnerability to sniffing and replay attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device's locally stored credentials (device fingerprint, certificate authority public key) act as intermediaries for security verification. Instead of centralized authentication, the device uses these intermediary credentials to independently verify server identity and establish secure connections without transmitting sensitive authentication data.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If pre-requisite user credentials are required, then authentication security is improved, but network growth and adoption are limited

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork growth
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The device performs self-authentication using credentials it already possesses (device fingerprint, stored certificate authority public key). New devices can autonomously authenticate to the network without requiring pre-provisioned user credentials or manual enrollment processes, enabling rapid network growth and adoption.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the authentication credential requirement from the network enrollment process. Devices use locally stored credentials (device fingerprint, certificate authority public key) for authentication without needing pre-requisite user credentials from the network administrator, simplifying onboarding and enabling network expansion.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10963870B2Method and system for network communication
Publication Date: 2021.03.30 VAPOSUN
  • US10963870B2 patent drawing
  • US10963870B2 patent drawing
  • US10963870B2 patent drawing

AI summary

Technologies are generally described for methods and systems effective to secure process synchronized requests after at least one secure inter-device communication link between the originating and confirming communication devices is established. A method may include forwarding, by the confirming communication device the request and receiving, by a server, a first request from the originating device and at least one second request from the confirming device. The method may also include, by the server, determining a sequence of receiving of the first and the at least one second requests and processing the requests in order to authenticate a communication device, accept or reject a financial transaction, based on the receiving sequence and receiving time difference.