Multi-factor Authentication via Cross-Channel Message Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network operators or service providers face challenges in authenticating mobile devices and user applications across multiple networks due to the non-sharing of SIM credentials, limiting access to services like voicemail.

Innovation Solution

Implementing a multi-factor authentication method where a mobile device receives and processes authentication requests through multiple communication channels, such as HTTP and SMS messages, to verify user identity and authenticate devices and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM credentials are used for network-based authentication, then authentication reliability is improved, but accessibility across multiple network operators deteriorates because SIM credentials are not shared across operators

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcross-network accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication system is segmented into multiple independent authentication factors (SIM credential verification, HTTP message verification, SMS message verification) that can operate independently or in combination. This allows the system to maintain high reliability through multiple verification layers while improving adaptability by supporting different authentication paths for different network scenarios.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary authentication mechanisms (HTTP messages, SMS messages, hash value verification) that mediate between the user device and the network operator. These intermediaries enable cross-network authentication without requiring direct SIM credential sharing, thus resolving the contradiction between authentication reliability and cross-network accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-factor authentication is implemented, then authentication security is improved, but system complexity increases due to multiple communication channels and verification steps

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The user device is designed with multi-functional capability to handle multiple types of authentication messages (HTTP, SMS) and perform various verification operations (hash comparison, credential validation). This universal design consolidates multiple authentication functions into a single integrated system, improving security while managing complexity through functional integration rather than proliferation of separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically changes authentication parameters (selecting which authentication factors to use, which communication channels to employ) based on the specific network context and service requirements. This allows the system to adapt its complexity level to match the security needs of each authentication scenario, maintaining high security when necessary while reducing complexity in routine scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11949674B2Multi-factor message authentication
Publication Date: 2024.04.02 COMCAST CABLE COMM LLC
  • US11949674B2 patent drawing
  • US11949674B2 patent drawing
  • US11949674B2 patent drawing

AI summary

Systems, methods, and apparatuses are described for authenticating a user device and/or user application. A user device may receive, based on a first authentication request, a plurality of messages sent over a plurality of channels of communication (e.g., a message to a URL address associated with the user device and a binary Short Message Service (SMS) message). Based on information from the messages, the user device may transmit a second authentication request.