Network-Based MFA Authentication for Secure SMS and App Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication methods in wireless communications networks, such as SMS-based pin codes, are insecure against malicious users with duplicate SIM cards or unauthorized applications, compromising user data and financial assets.

Innovation Solution

Implement a network exposure entity and policy control entity to manage authentication requests from service providers, using identifiers and criteria to ensure secure SMS delivery and application-level authentication within the wireless communications network, enhancing security through per-user and per-application authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SMS-based pin code authentication is used, then authentication can be provided to external service providers, but security is compromised against malicious users with duplicate SIM cards or unauthorized applications

Engineering Contradiction:
Improveauthentication capability for external service providersVSAvoidsecurity against malicious users
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple independent verification stages: (1) service provider identity verification against a database of authorized providers, (2) application identifier verification to ensure the app is authorized for the user's device, and (3) SIM card authentication. This multi-layered segmentation prevents malicious users from bypassing security by duplicating only part of the authentication mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network exposure entity and policy control entity as intermediaries between the SMS authentication system and external service providers. These intermediaries verify service provider identities, validate application identifiers, and authorize authentication requests before allowing SMS delivery. This intermediary layer acts as a security gatekeeper that prevents unauthorized access while maintaining legitimate authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network exposure entity and policy control entity are implemented for secure authentication, then security is enhanced through per-user and per-application verification, but device complexity increases

Engineering Contradiction:
Improvesecurity through per-user and per-application verificationVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework where the network exposure entity and policy control entity serve multiple functions: they authenticate service providers, validate application identifiers, verify user identities, and manage SMS delivery authorization. This multi-functional approach consolidates what could be separate complex systems into integrated network entities, reducing overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary verification of service provider identities and application identifiers before allowing authentication requests to proceed. By pre-authorizing service providers and validating application-user associations in advance, the system eliminates the need for complex real-time decision-making during authentication, simplifying the operational complexity while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12556525B2Network supported authentication
Publication Date: 2026.02.17 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12556525B2 patent drawing
  • US12556525B2 patent drawing
  • US12556525B2 patent drawing

AI summary

Embodiments of the invention can relate to various methods for operating a network exposure entity (270) and/or a policy control entity in a wireless communications network (200), in which a data packet session can be provided between a service provider (300) and a user equipment (100), the methods comprising steps for enabling the wireless communications network (200) to take an active role in a multi-factor authentication procedure requested by the service provider (300). Further embodiments of the invention relate to respective network exposure entities (270) and/or policy control entities.