Mobile Device Offline Authentication via Stored Challenge-Response Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SIM-based authentication mechanisms for mobile devices are limited as they require network connectivity, are vulnerable to spoofing attacks, and do not provide adequate encryption and integrity verification for locally stored data.

Innovation Solution

A method that uses a first identity module to authenticate with a communication network when connected, storing challenge-response data for offline authentication with a second identity module, and employing security algorithms for encryption and integrity verification, while preventing spoofing attacks through a security manager module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If (U)SIM-based authentication is used to secure local resources, then authentication security is improved, but the system becomes vulnerable to spoofing attacks and requires network connectivity

Engineering Contradiction:
Improveauthentication securityVSAvoidspoofing attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by collecting and storing challenge-response authentication data during online sessions before offline access is needed. This pre-stored authentication data enables the system to verify identity without requiring real-time network connectivity, thus resolving the contradiction between security and offline accessibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (the authentication data storage and verification system) that mediates between the (U)SIM authentication function and the local resource access function. This intermediary stores authentication results and enables offline verification, eliminating the need for continuous network connectivity while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If (U)SIM-based authentication is used for securing local resources, then authentication capability is improved, but encryption and integrity verification for locally stored data are not provided

Engineering Contradiction:
Improveauthentication capabilityVSAvoiddata confidentiality and integrity vulnerability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent merges multiple security functions into a unified system: (U)SIM authentication, challenge-response verification, data encryption, and integrity checking are combined into a single security framework. This integration allows the system to provide both authentication and data protection capabilities simultaneously

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security system uses composite security mechanisms that combine different security primitives: authentication protocols, encryption algorithms, and integrity verification methods work together as a composite security structure. This composite approach provides comprehensive protection for both authentication and data integrity

Inventive Principle:
Principle #40Composite materials

3Reliability

If network connectivity is required for authentication, then authentication security is improved, but access to local resources becomes unavailable when offline

Engineering Contradiction:
Improveauthentication securityVSAvoidoffline access availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication data collection during online sessions and stores it for later use. This preliminary action enables the system to maintain security verification capability without requiring real-time network connectivity, thus resolving the contradiction between security and offline accessibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the authentication verification capability that can operate independently of the network. By storing challenge-response data pairs, the system creates a portable authentication verification mechanism that functions offline, eliminating the dependency on continuous network connectivity

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9094823B2Data processing for securing local resources in a mobile device
Publication Date: 2015.07.28 ORANGE SA
  • US9094823B2 patent drawing
  • US9094823B2 patent drawing
  • US9094823B2 patent drawing

AI summary

A method of data processing for securing local resources in a mobile device. The method includes: a) when network connectivity is available: coupling the mobile device with a first identity module associated to a first International Mobile Subscriber Identity (IMSI), receiving in the first identity module a network challenge from a communication network, ciphering the network challenge using a secret key, and sending a corresponding response to the network for subsequent successful authentication, b) after a successful authentication to the communication network: associating at least a part of the local resources to the first IMSI, and storing, in a database of the mobile device, authentication data related to the challenge/response duplet, granting access to local resources associated to the first IMSI.