Mobile Number Security via Trusted Device Code Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There has been a significant increase in mobile device identification takeovers, leading to various security issues for users and service providers, as bad actors can gain control of wireless device accounts and associated phone numbers, allowing them to access sensitive information and services.
Innovation Solution
A system and process are implemented to enhance mobile number security protections by generating a system-generated code based on time-dependent, encryption, and device-related data, which is compared to a wireless device-generated code to authorize transactions, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional 2 factor SMS authentication is implemented, then ease of operation is improved, but security is worsened because bad actors can receive SMS messages on taken-over mobile devices
Solution Approach 1:
The patent introduces a trusted device as an intermediary component that generates and verifies authentication codes. This trusted device acts as a mediator between the user's mobile device and the service provider, creating a secure channel that bypasses the vulnerable SMS authentication path while maintaining ease of use through the familiar code verification process.
Solution Approach 2:
The authentication system is segmented into multiple independent components: the trusted device that generates codes, the mobile device that provides device identifiers, and the service provider that verifies authentication. This segmentation isolates the security-critical code generation from the potentially compromised mobile device and SMS channel, allowing each component to perform its function securely.
2Reliability
If mobile device identification takeover prevention is strengthened, then security is improved, but device complexity increases due to multiple verification layers
Solution Approach 1:
The trusted device automatically performs authentication code generation and verification without requiring user intervention beyond initial setup. The system uses device identifiers and timestamps to self-generate unique codes, eliminating the need for complex manual verification processes while maintaining strong security against device takeover attacks.
Solution Approach 2:
The trusted device is pre-configured with device identifiers and cryptographic keys before authentication is needed. This preliminary setup allows the system to quickly generate and verify authentication codes in real-time without adding complexity to the authentication flow, as the heavy cryptographic work has already been prepared in advance.
3Reliability
If real-time code verification is implemented, then security is improved, but processing time increases due to cryptographic operations
Solution Approach 1:
Cryptographic keys and device identifiers are pre-computed and stored in the trusted device before authentication is required. This preliminary preparation allows the system to perform rapid code generation and verification using pre-computed values, minimizing real-time processing delays while maintaining strong cryptographic security.
Solution Approach 2:
The authentication code incorporates a timestamp component that changes dynamically with each authentication attempt. This dynamic element ensures that each code is unique and time-sensitive, allowing the system to verify authentication quickly by comparing timestamps rather than performing complex cryptographic analysis on each attempt.
Data Source
AI summary
A system configured to implement mobile number security protections includes a computer system configured to obtain one or more of time dependent data, encryption data, and device related data; the computer system is further configured to generate a system generated code based on one or more of the time dependent data, the encryption data, and the device related data; the computer system is further configured to receive a wireless device generated code generated by a wireless device; and the computer system is further configured to compare the wireless device generated code generated by the wireless device to the system generated code generated by the computer system.


