Network Operator Authentication Server for Mobile Identity Federation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile applications lack robust authentication mechanisms, as existing methods like smartcards and TPM technology are not applicable on mobile devices, and user-friendly alternatives like one-time-passwords are cumbersome, while network operators have strong authentication mechanisms that are not effectively utilized.

Innovation Solution

The proposed solution leverages identity federation between network operators and mobile applications, using a network operator's security token server to authenticate mobile clients, issuing a proof of authentication that allows secure access to applications, thereby providing a seamless user experience and increasing customer value for operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication mechanisms (smartcards, TPM) are used on mobile devices, then authentication strength is improved, but device compatibility deteriorates

Engineering Contradiction:
Improveauthentication strengthVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a network operator authentication server as an intermediary between the mobile device and the application. The server handles the complex authentication operations using strong cryptographic mechanisms, while the mobile device only needs to communicate with the server through standard protocols. This mediator approach allows strong authentication to be achieved without requiring specialized hardware on the mobile device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If one-time-password (OTP) authentication is implemented on mobile devices, then device compatibility is improved, but user experience deteriorates

Engineering Contradiction:
Improvedevice compatibilityVSAvoiduser experience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system enables self-service authentication where the user's mobile device automatically interacts with the network operator's authentication server. The device itself performs the authentication operations using its capabilities, eliminating the need for manual OTP entry or external authentication tokens. This makes the process both compatible with standard mobile devices and user-friendly.

Inventive Principle:
Principle #25Self-service

3Reliability

If network operator authentication mechanisms are directly integrated into mobile applications, then authentication strength is improved, but system complexity deteriorates

Engineering Contradiction:
Improveauthentication strengthVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network operator authentication server acts as an intermediary that encapsulates the complex authentication logic. Mobile applications only need to communicate with this server through standardized protocols, without needing to implement or understand the complex cryptographic mechanisms. This reduces system complexity for application developers while maintaining strong authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If federated identity authentication is implemented, then ease of operation is improved, but trust management complexity deteriorates

Engineering Contradiction:
Improveuser experienceVSAvoidtrust management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The network operator authentication server serves as a trusted intermediary that manages the federation trust relationships. It handles the complex trust management, certificate validation, and identity mapping between different authentication domains. This allows federated identity authentication to work seamlessly for users while the trust management complexity is contained within the server infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8881247B2Federated mobile authentication using a network operator infrastructure
Publication Date: 2014.11.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8881247B2 patent drawing
  • US8881247B2 patent drawing
  • US8881247B2 patent drawing

AI summary

Architecture that utilizes the strong authentication mechanisms of network operators to provide authentication to mobile applications by identity federation. When a mobile client initiates request for access to an application outside the network operation infrastructure, the request is passed to an associated application secure token service. The application secure token service has an established trust and identity federation with the network operator. The application secure token service redirects the request to a network operator security token server, which then passes the request to a network operator authentication server for authentication against an operator identity service. Proof of authentication is then issued and returned from the network operator security token server to the application secure token service and the application, which allows the mobile client to access the application.