Network-Based MFA Authentication for Secure SMS and App Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-factor authentication methods in wireless communications networks, such as SMS-based pin codes, are insecure against malicious users with duplicate SIM cards or unauthorized applications, compromising user data and financial assets.
Innovation Solution
Implement a network exposure entity and policy control entity to manage authentication requests from service providers, using identifiers and criteria to ensure secure SMS delivery and application-level authentication within the wireless communications network, enhancing security through per-user and per-application authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If SMS-based pin code authentication is used, then authentication can be provided to external service providers, but security is compromised against malicious users with duplicate SIM cards or unauthorized applications
Solution Approach 1:
The patent segments the authentication process into multiple independent verification stages: (1) service provider identity verification against a database of authorized providers, (2) application identifier verification to ensure the app is authorized for the user's device, and (3) SIM card authentication. This multi-layered segmentation prevents malicious users from bypassing security by duplicating only part of the authentication mechanism.
Solution Approach 2:
The patent introduces a network exposure entity and policy control entity as intermediaries between the SMS authentication system and external service providers. These intermediaries verify service provider identities, validate application identifiers, and authorize authentication requests before allowing SMS delivery. This intermediary layer acts as a security gatekeeper that prevents unauthorized access while maintaining legitimate authentication functionality.
2Reliability
If network exposure entity and policy control entity are implemented for secure authentication, then security is enhanced through per-user and per-application verification, but device complexity increases
Solution Approach 1:
The patent implements a universal authentication framework where the network exposure entity and policy control entity serve multiple functions: they authenticate service providers, validate application identifiers, verify user identities, and manage SMS delivery authorization. This multi-functional approach consolidates what could be separate complex systems into integrated network entities, reducing overall system complexity while maintaining comprehensive security.
Solution Approach 2:
The patent performs preliminary verification of service provider identities and application identifiers before allowing authentication requests to proceed. By pre-authorizing service providers and validating application-user associations in advance, the system eliminates the need for complex real-time decision-making during authentication, simplifying the operational complexity while maintaining high security standards.
Data Source
AI summary
Embodiments of the invention can relate to various methods for operating a network exposure entity (270) and/or a policy control entity in a wireless communications network (200), in which a data packet session can be provided between a service provider (300) and a user equipment (100), the methods comprising steps for enabling the wireless communications network (200) to take an active role in a multi-factor authentication procedure requested by the service provider (300). Further embodiments of the invention relate to respective network exposure entities (270) and/or policy control entities.


