Operator-Network Authentication with Encrypted Physiological Data Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in ensuring the authenticity and integrity of communication content, particularly in the face of telecommunication fraud facilitated by AI face swapping and voice change technologies, necessitating a reliable method to verify the identity of callers and prevent fraudulent activities.

Innovation Solution

An authentication method involving a first operator network device that performs authentication on a user's trustworthiness, generates a signature, and sends it to a second user or network device, utilizing physiological characteristic information encrypted by a third-party authentication authority, thereby ensuring the authenticity of communication content without storing sensitive user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If operator network devices store physiological characteristic information for authentication, then authentication reliability is improved, but security risks and data privacy concerns increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive physiological characteristic information from the operator network device's storage scope. Instead of storing raw physiological data, the system only retains authentication results and signatures. The physiological information is processed into encrypted forms or temporary authentication tokens that are discarded after use, effectively removing the security risk source while preserving authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where physiological characteristic information serves as an intermediate step only. The system uses this information to generate authentication signatures through a trusted third party or secure element, then discards the original physiological data. This intermediary approach enables reliable authentication without creating security vulnerabilities from data storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive authentication methods are implemented to verify caller identity, then telecommunication fraud prevention is improved, but system complexity increases

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional modules: physiological characteristic collection, encryption processing, signature generation, and verification. Each module performs a specific task in the authentication chain. This segmentation allows the complex authentication process to be implemented through standardized, independent components that can be managed and maintained separately, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal authentication framework that can handle multiple authentication scenarios (voice calls, video calls, messaging) through a common signature-based mechanism. The authentication apparatus works across different communication types and network operators using standardized protocols, eliminating the need for separate authentication systems for each scenario and thereby reducing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If authentication signatures are transmitted with each communication message, then message authenticity is improved, but communication overhead increases

Engineering Contradiction:
Improvemessage authenticityVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by transmitting authentication signatures selectively rather than uniformly. Signatures are attached based on the specific communication context - for example, only on call setup messages, or only when suspicious activity is detected, or only for high-value transactions. This selective application reduces the overall quantity of authentication data transmitted while maintaining authenticity verification where most critical.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial authentication action by using different authentication strengths for different scenarios. For routine communications, lightweight signature verification is used. For high-risk scenarios, more comprehensive authentication is applied. This partial approach balances message authenticity requirements with data transmission efficiency, avoiding excessive authentication overhead in low-risk situations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4362515B1Authentication method and apparatus
Publication Date: 2025.08.27 HUAWEI TECH CO LTD
  • EP4362515B1 patent drawingFigure 1~2
  • EP4362515B1 patent drawingFigure 3~4
  • EP4362515B1 patent drawingFigure 5A

AI summary

This application provides an authentication method and apparatus. The authentication method includes: A first operator network device performs authentication on whether a first user is trustworthy, to obtain a first authentication result, where the first user is a user who sends a message to the first operator network device by using a first terminal device; the first operator network device signs the first authentication result to generate a first signature; and the first operator network device sends the first authentication result and the first signature to a second terminal device used by a second user or to a second operator network device, where the second operator network device is an operator network device that provides a service for the second user, and the second user is a user called by the first user. Authentication is performed on whether the user is trustworthy, to ensure that communication content in an end-to-end communication process is authentic and is not tampered with, and avoid or reduce telecommunication fraud.