Network-Assisted Secure Access Application for Mobile Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multi-factor authentication methods are vulnerable to interception attacks, as attackers can compromise the second factor, such as a code or token, during the access process, compromising user data security.

Innovation Solution

A network-assisted secure access application on user devices that leverages mobile connectivity data and user profiles to enhance two-factor authentication by validating mobile connectivity data against a fraud database and providing a security key for secure access to resources, ensuring continuous authentication and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication is implemented, then security against malicious attacks is improved, but vulnerability to interception attacks during the access process persists

Engineering Contradiction:
ImprovesecurityVSAvoidinterception vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security server as an intermediary between the user device and the secure resource. This mediator validates mobile connectivity data and generates security keys that protect the authentication process from interception attacks, thereby resolving the vulnerability while maintaining multi-factor authentication security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary validation of mobile connectivity data against a fraud database before the actual authentication process. By pre-establishing the legitimacy of the device's network connection and generating security keys in advance, the system prevents interception attacks during the critical authentication phase

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional two-factor authentication is used, then access security is enhanced, but the authentication process becomes more complex and less seamless

Engineering Contradiction:
Improveaccess securityVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables the user device to automatically obtain mobile connectivity data and perform self-validation through the security server without requiring user intervention. The device autonomously receives security keys and completes the authentication process, making the enhanced security transparent and seamless for the user

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent combines mobile connectivity validation with the traditional two-factor authentication process. By integrating these security measures into a unified authentication flow handled by the security server, the system maintains strong security while presenting a simplified, seamless user experience

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11757939B2Network-assisted secure data access
Publication Date: 2023.09.12 AT&T MOBILITY II LLC
  • US11757939B2 patent drawing
  • US11757939B2 patent drawing
  • US11757939B2 patent drawing

AI summary

The concepts and technologies disclosed herein provide a network-assisted secure access (“NASA”) application that is installed on a user device. The NASA application can enhance current multi-factor authentication processes to prevent unauthorized access by leveraging mobile connectivity data. The enhanced two-factor authentication process is made seamless and transparent to the user by authenticating the mobile connectivity data with data known to the mobile network that serves the user device. The mobile connectivity data can include network-determined location, cell identifier (“cell ID”), Internet protocol (“IP”) address, a globally unique temporary identifier (“GUTI”), combinations thereof, and the like. Additionally or alternatively, one or more user profiles (e.g., user-defined and/or social media profile(s)) can be used to further enhance security. The enhanced two-factor authentication process can be executed at initial access to establish a secure connection and/or at any time during an established connection to ensure the connection remains secure.