Mobile Terminal Authentication via Subscriber Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile authentication methods require users to manually input their MSISDN number, which hinders user convenience and security, as applications on mobile phones cannot access this information without user intervention, and rely on personal data stored in the SIM card.

Innovation Solution

A method where the mobile terminal sends a subscriber identifier, such as IMSI or ICCID, to an application server, which then processes authentication requests without requiring the user to input their MSISDN number, using a security module to generate a unique authentication code for service access, minimizing changes to existing authentication systems and ensuring secure, transparent authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the user manually inputs their MSISDN number for authentication, then the authentication can be performed, but the user convenience and speed of access are reduced

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile terminal automatically extracts its own MSISDN number from its identification data without requiring user intervention. The terminal serves itself by using its built-in identification capabilities to provide authentication information, eliminating the need for manual input while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The MSISDN number is pre-stored in the mobile terminal's identification data, ready for use. When authentication is needed, the terminal can immediately access and transmit this pre-existing data without requiring the user to manually input anything, thus improving both convenience and authentication reliability.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the application extracts MSISDN from the mobile terminal without user intervention, then user convenience is improved, but the application cannot access the MSISDN number due to security restrictions

Engineering Contradiction:
Improveuser convenienceVSAvoidaccess mechanism complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent uses an intermediary mechanism where the mobile terminal itself acts as the mediator between the application and the MSISDN data. The terminal's identification system provides the MSISDN number to the application through standardized interfaces, avoiding direct access restrictions while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the authentication method depends on personal data stored in the SIM card, then authentication can be performed, but the method becomes less flexible and harder to implement without modifications

Engineering Contradiction:
Improveauthentication capabilityVSAvoidimplementation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The mobile terminal's identification system serves multiple functions: it stores the MSISDN number, provides authentication capabilities, and enables service access. This multi-functional approach eliminates the need for separate authentication mechanisms and simplifies implementation while maintaining reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3682661B1Access to a service with authentication based on a mobile terminal
Publication Date: 2024.08.14 ORANGE SA
  • EP3682661B1 patent drawingFigure 1
  • EP3682661B1 patent drawingFigure 2
  • EP3682661B1 patent drawingFigure 3

AI summary

The invention concerns a method for accessing a service supplied on a mobile terminal (T2) by a server contributing to supplying the service, termed the application server (SP2), the method being implemented by the mobile terminal and comprising the following steps: · transmitting (G1) a request (TRq0) comprising an identifier of a subscriber of a subscription with a mobile operator (MNO), termed the subscriber identifier (MNOSiD1), the subscriber identifier being based on a piece of information supplied by a security module of the mobile terminal, and inserted in the request (TRq0) without intervention of the user; · receiving (G4) a response (TRp0) comprising a piece of information relating to the subscriber identifier (MNOSiD1), termed the identification code (temp Alias); · transmitting (G9) an authentication request (Auth Rq) comprising the identification code (temp Alias), the request (Auth Rq) being transmitted to an authentication server (AUTH) of the mobile operator (MNO); · receiving (G12) an authentication response (Auth Rp) comprising a piece of information relating to the identification code (temp Alias), termed the authentication code (auth Code); · transmitting (G13) a service access request (SRq) comprising the authentication code (auth Code), the request (SRq) being transmitted to the application server (SP2).