Mobile Operator Security Server Personalized Service Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile authentication technologies lack a flexible and customizable security mechanism that balances security and convenience, as they often impose uniform security levels across different online services, which may be overly burdensome for non-sensitive services and insufficient for sensitive ones.

Innovation Solution

A method that allows users to define personalized security levels for each online service by associating unique identifiers with service-specific security parameters, enabling varying validation procedures such as interface manipulation, authentication codes, or biometric verification, and allowing users to modify these settings based on their preferences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uniform high security validation procedures are applied to all online services, then security level is improved, but ease of operation deteriorates due to unnecessary burden on non-sensitive services

Engineering Contradiction:
Improvesecurity levelVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different security validation procedures to different online services based on their sensitivity. Each service can be configured with its own security level (e.g., simple button press for non-sensitive services, PIN code or biometric verification for sensitive services), allowing the security measure to be tailored locally to each service's requirements rather than applying a uniform high security level across all services.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security validation procedure is made dynamic and adaptable. The system can adjust the required validation level based on the service being accessed, user preferences, and potentially other factors. This dynamic approach allows the security mechanism to be stringent when needed and lenient when not needed, resolving the contradiction between maintaining high security and ensuring ease of operation.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple authentication mechanisms are required for sensitive services, then security level is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent validation mechanisms (button press, PIN code, biometric verification) that can be selectively applied. Rather than implementing a single complex multi-factor authentication system for all services, the patent divides the authentication process into separate, manageable validation steps that can be configured independently for each service, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies authentication mechanisms partially - only the necessary level of validation is applied to each service based on its sensitivity. For non-sensitive services, only simple validation is applied; for sensitive services, additional validation layers are added. This partial application of authentication mechanisms avoids the complexity of requiring all authentication types for every service while still providing enhanced security where needed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10984131B2Method for providing personal information of a user requested by a given online service
Publication Date: 2021.04.20 ORANGE SA
  • US10984131B2 patent drawing

AI summary

A method for providing personal information of a user requested by a given online service. The method includes, by a security server of a mobile terminal operator of be user: (a) receiving a request for the personal information, including comprising a unique identifier of the user and an identifier of the online service; (b) sending, to the mobile terminal, a response authorisation request; (c) if a response authorisation confirmation is received, sending data, which is associated in a database with the unique identifier and the identifier of the online service. Each pair of a unique identifier and an online service identifier is also associated in the database with a parameter representative of a level of security required in order to confirm the response authorisation on the mobile terminal. The step (b) includes: determining the value of the parameter; and integrating the determined value in the response authorisation request.