Mobile Station Proxy Authentication for Wireless Traffic Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Open ID service in communication systems requires numerous message transmissions and receptions, leading to increased wireless traffic and prolonged login times, and is primarily designed for computer-centered web browser environments, necessitating improvements for mobile device compatibility and efficiency.

Innovation Solution

A method and apparatus for user authentication by proxy in a communication system, where a mobile station manages security identification and authentication processes, reducing message transmissions through a simplified process using a Mobile Security Information Manager (MOSIM) that generates a permanent authentication key for subsequent authentications, and implements a double check scheme to enhance security and reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the existing Open ID service is used for user authentication, then user authentication can be performed through a third party organization, but the number of message transmissions increases and authentication time is prolonged

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the mobile station generate and store authentication information in advance before actual authentication is needed. The authentication agent creates authentication data locally on the mobile device, so that when authentication is required, the pre-generated information can be immediately used without requiring multiple back-and-forth message exchanges with the authentication server, thus reducing authentication time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the authentication information generation process from the centralized authentication server and places it locally on the mobile station. By taking out the authentication agent and its ability to generate authentication data independently, the system reduces the number of messages that need to be transmitted to the server, thereby decreasing authentication time while preserving the reliability of third-party authentication

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the existing Open ID service is used for user authentication, then user authentication can be performed through a third party organization, but the number of message transmissions increases and wireless traffic is increased

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidwireless traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The authentication information generation function is extracted from the network side and embedded locally in the mobile station's authentication agent. This extraction eliminates the need for multiple message transmissions to the authentication server during the authentication process, thereby reducing wireless traffic while maintaining the reliability of third-party authentication services

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile station performs self-service authentication by generating authentication information locally using the authentication agent. Instead of relying on the network to provide authentication data through multiple message exchanges, the mobile device serves itself by creating the necessary authentication credentials locally, thus reducing wireless traffic while maintaining authentication reliability

Inventive Principle:
Principle #25Self-service

3Productivity

If authentication information is stored in the mobile station for rapid authentication, then authentication time is reduced, but security risks increase

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by implementing different security mechanisms for different locations in the system. The authentication agent stored in the mobile station uses secure element technology to provide enhanced local security for storing and generating authentication information. This localized security enhancement allows rapid authentication using pre-generated credentials while maintaining high security standards through the secure element's protected environment

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses composite materials by combining the authentication agent software with hardware-based secure element technology. This composite approach integrates software-based authentication logic with hardware-based security protection, enabling both fast authentication through local information generation and high security through the secure element's protected storage and processing capabilities

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS9419974B2Apparatus and method for performing user authentication by proxy in wireless communication system
Publication Date: 2016.08.16 SAMSUNG ELECTRONICS CO LTD
  • US9419974B2 patent drawing
  • US9419974B2 patent drawing
  • US9419974B2 patent drawing

AI summary

A method of performing user authentication of a mobile station by proxy in a communication system is provided. The method includes receiving an authentication request, which requests authentication of a user, from an Internet service provider having received information indicating that the mobile station can perform authentication based on only the mobile station's own information, requesting the user to provide security identification information for authentication, receiving the security identification information input by the user, authenticating the user by determining whether the security identification information is valid information, through security-requiring information managed by the mobile station, and transmitting an authentication result to the Internet service provider and receiving an authorized authentication result from the Internet service provider and providing a service according to the authorized authentication result to the user.