Mobile Station Location Verification for Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods in telecommunication networks are vulnerable to attacks such as eavesdropping, replay attacks, and dictionary attacks, especially in public data networks like the Internet, due to the susceptibility of password-based systems to interception and manipulation, which can lead to unauthorized access and loss of control over systems.

Innovation Solution

A method that uses a mobile station and an authentication server to authenticate users by verifying location information, potentially using one-time passwords, and incorporating PIN codes and encryption with public and private keys to ensure secure access to services, leveraging the intrinsic security of GSM networks and location-sensitive access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based authentication is used in public data networks, then ease of operation is improved, but security is worsened due to susceptibility to eavesdropping, replay attacks, and dictionary attacks

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by requiring the mobile station to present location information (such as cell ID, latitude/longitude) to the authentication server before authentication is granted. This pre-verification of location ensures that even if password information is intercepted, it cannot be reused from unauthorized locations, preventing replay attacks while maintaining ease of operation through automated location verification.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If location information verification is added to authentication, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses the mobile network infrastructure (base stations, location servers) as an intermediary to obtain and verify location information. The authentication server acts as a mediator that coordinates between the mobile station, location information sources, and service providers. This intermediary approach avoids direct complex implementation in end devices while enhancing security through centralized verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If one-time passwords are used instead of reusable passwords, then security is improved against replay attacks, but ease of operation is worsened due to frequent password changes

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the parameter being verified from password-only to location-based verification. Instead of requiring frequent password changes, the system verifies that the mobile station is at an authorized location (using parameters like cell ID, geographic coordinates, or network-identified location). This parameter change maintains security against replay attacks while preserving user convenience, as location is automatically determined by the network infrastructure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8423768B2Method for controlling the location information for authentication of a mobile station
Publication Date: 2013.04.16 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US8423768B2 patent drawing
  • US8423768B2 patent drawing
  • US8423768B2 patent drawing

AI summary

The method is for authentication in a communication network. A mobile station and an authentication server give access to services in the network. A user of a mobile station first sends a request for a service or a password in a message from the mobile station. The authentication server controls the location information for the mobile station, and sends a password to the mobile station or grants access to the user as a reply to the request if the location information is accepted by the server.