Mobile Terminal Authentication via SIM and Device Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication systems face security challenges as stolen mobile terminals can be easily used with new SIM cards, leading to economic loss and inconvenience for legal users, and existing security measures like passwords and equipment identification registers are either inconvenient or costly to implement and maintain.

Innovation Solution

A method where network equipment generates authentication information based on a security key and a random number, which is used by mobile terminals to authenticate the network, ensuring secure access and preventing unauthorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile terminals are separated from user cards (SIM/USIM/UIM), then user convenience is improved (easy to change terminals), but security deteriorates (stolen terminals can be used with new SIM cards)

Engineering Contradiction:
ImproveUser convenience in changing terminalsVSAvoidTerminal security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides authentication into two independent parts: network authentication (performed by SIM card) and terminal authentication (performed by mobile terminal itself). This segmentation allows the SIM card to remain for user identification while the terminal performs device-specific authentication, resolving the security issue without affecting user convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mobile terminal acts as an intermediary that performs authentication based on terminal identification information before allowing network access. This intermediary layer prevents stolen terminals from being used even with valid SIM cards, as the terminal itself must authenticate.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If passwords are set for mobile terminals, then security is improved (thieves cannot use stolen terminals), but user convenience deteriorates (users must input password every startup)

Engineering Contradiction:
ImproveTerminal securityVSAvoidUser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile terminal performs automatic authentication with the network based on its terminal identification information, without requiring user intervention or password input. The terminal serves itself by autonomously verifying its authenticity, eliminating the need for manual password entry while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If equipment identification registers (EIR) are established to blacklist stolen terminals, then security is improved (stolen terminals cannot access network), but device complexity and cost increase (require additional network equipment)

Engineering Contradiction:
ImproveTerminal securityVSAvoidNetwork equipment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication function is extracted from the network side EIR system and embedded directly in the mobile terminal. Each terminal performs self-authentication using its own terminal identification information, eliminating the need for complex network-side blacklisting infrastructure while achieving the same security effect.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If equipment identification registers (EIR) are established to blacklist stolen terminals, then security is improved, but loss of time increases (authentication procedures become complex)

Engineering Contradiction:
ImproveTerminal securityVSAvoidAuthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The mobile terminal pre-stores its terminal identification information and performs authentication automatically during the normal network attachment process. This preliminary preparation allows authentication to occur seamlessly without additional time-consuming procedures or user intervention.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8909193B2Authentication method
Publication Date: 2014.12.09 HUAWEI TECH CO LTD
  • US8909193B2 patent drawing
  • US8909193B2 patent drawing
  • US8909193B2 patent drawing

AI summary

A method for network equipment to generate authentication information in the mobile communication system, at least includes the following process: set security key corresponding to mobile terminal in network equipment; and network equipment generates authentication information corresponding to mobile terminal based on said security key and a random number. And, a method for mobile terminal to authenticate communication network in the mobile communication network, at least includes the following process: set security key corresponding to mobile terminal in the mobile terminal; and after the authentication information from network equipment is received, the mobile terminal determines whether the network authentication succeeds based on said security key set by the mobile terminal and the authentication information. An authentication method in mobile communication network is also disclosed, and includes the following process: the mobile terminal authenticates the network, and the network authenticates the mobile terminal.