Mobile Device Offline Authentication via Stored Challenge-Response Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current SIM-based authentication mechanisms for mobile devices are limited as they require network connectivity, are vulnerable to spoofing attacks, and do not provide adequate encryption and integrity verification for locally stored data.
Innovation Solution
A method that uses a first identity module to authenticate with a communication network when connected, storing challenge-response data for offline authentication with a second identity module, and employing security algorithms for encryption and integrity verification, while preventing spoofing attacks through a security manager module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If (U)SIM-based authentication is used to secure local resources, then authentication security is improved, but the system becomes vulnerable to spoofing attacks and requires network connectivity
Solution Approach 1:
The system performs preliminary actions by collecting and storing challenge-response authentication data during online sessions before offline access is needed. This pre-stored authentication data enables the system to verify identity without requiring real-time network connectivity, thus resolving the contradiction between security and offline accessibility
Solution Approach 2:
The patent introduces an intermediary mechanism (the authentication data storage and verification system) that mediates between the (U)SIM authentication function and the local resource access function. This intermediary stores authentication results and enables offline verification, eliminating the need for continuous network connectivity while maintaining security
2Reliability
If (U)SIM-based authentication is used for securing local resources, then authentication capability is improved, but encryption and integrity verification for locally stored data are not provided
Solution Approach 1:
The patent merges multiple security functions into a unified system: (U)SIM authentication, challenge-response verification, data encryption, and integrity checking are combined into a single security framework. This integration allows the system to provide both authentication and data protection capabilities simultaneously
Solution Approach 2:
The security system uses composite security mechanisms that combine different security primitives: authentication protocols, encryption algorithms, and integrity verification methods work together as a composite security structure. This composite approach provides comprehensive protection for both authentication and data integrity
3Reliability
If network connectivity is required for authentication, then authentication security is improved, but access to local resources becomes unavailable when offline
Solution Approach 1:
The system performs preliminary authentication data collection during online sessions and stores it for later use. This preliminary action enables the system to maintain security verification capability without requiring real-time network connectivity, thus resolving the contradiction between security and offline accessibility
Solution Approach 2:
The patent creates a copy of the authentication verification capability that can operate independently of the network. By storing challenge-response data pairs, the system creates a portable authentication verification mechanism that functions offline, eliminating the dependency on continuous network connectivity
Data Source
AI summary
A method of data processing for securing local resources in a mobile device. The method includes: a) when network connectivity is available: coupling the mobile device with a first identity module associated to a first International Mobile Subscriber Identity (IMSI), receiving in the first identity module a network challenge from a communication network, ciphering the network challenge using a secret key, and sending a corresponding response to the network for subsequent successful authentication, b) after a successful authentication to the communication network: associating at least a part of the local resources to the first IMSI, and storing, in a database of the mobile device, authentication data related to the challenge/response duplet, granting access to local resources associated to the first IMSI.


