Mobile Operator Authentication Delegation for Service Providers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems in communication networks require Service Providers to handle registration and authentication procedures independently, leading to high costs and user unfriendliness, as users must establish separate trust relations with each Service Provider, which is inefficient and prone to fraud due to weak authentication methods.
Innovation Solution
A method where a Mobile Operator acts as the Registration Authority, performing strong authentication with subscribers and generating a Mobile Strong Authentication Assertion (MSAA) that can be validated by Service Providers, allowing delegation of authentication procedures and enabling secure bootstrapping and enrollment, leveraging existing trusted relationships.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Service Providers handle registration and authentication independently, then authentication security can be maintained, but authentication costs increase and user convenience deteriorates
Solution Approach 1:
The patent segments the authentication system into two distinct roles: Registration Authority (RA) handled by the Mobile Operator and Certificate Authority (CA) handled by the Service Provider. This segmentation allows the operator to perform user authentication and registration, while the service provider only needs to validate certificates, thereby reducing authentication costs and improving user convenience while maintaining security through role separation.
Solution Approach 2:
The patent introduces a Mobile Strong Authentication Assertion (MSAA) as an intermediary mechanism. The MSAA serves as a trusted credential issued by the operator's RA that the service provider's CA can validate. This intermediary allows the service provider to trust the operator's authentication without needing to perform its own registration procedures, reducing costs and improving user experience.
2Reliability
If Service Providers establish separate trust relations with users, then authentication reliability can be ensured, but system complexity and costs increase
Solution Approach 1:
The patent makes the Mobile Operator's Registration Authority universal by enabling it to serve multiple Service Providers simultaneously. The operator's RA issues MSAA credentials that can be validated by any service provider's CA that has established a trust relationship with the operator. This universality eliminates the need for each service provider to maintain separate registration systems, reducing overall system complexity while maintaining authentication reliability.
3Reliability
If face-to-face registration procedures are used, then authentication security is improved, but registration costs and time consumption increase
Solution Approach 1:
The patent replaces the mechanical face-to-face registration process with an electronic authentication system. The operator's RA performs strong authentication electronically using existing subscriber credentials (such as SIM-based authentication), eliminating the need for physical document verification and in-person meetings. This substitution maintains security through strong cryptographic authentication while dramatically reducing registration time and cost.
Data Source
AI summary
The present invention is related to an authentication method and arrangements in a communication system including a Subscriber (50) with a terminal (51), an Operator Node (52) and a Service Provider Node (53), which authentication method is based on an SLA agreement between the Operator (OP) and the Service Provider (SP). The method includes that the Subscriber (50) with terminal (51) performs (5) strong authentication with the Operator Node (52) acting as Registration Authority OP(RA). After the strong authentication is performed by the Operator Node (52) a Mobile Strong Authentication Assertion MSAA is generated (6) and transmitted to the Service Provider Node (53) for validation. By this method the authentication is being delegated from the Service Provider to the Mobile Operator.


