Mutual Authentication via Third-Party Portal Using Security Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for mutual authentication between a user terminal and a remote server via a third-party portal are vulnerable to security attacks, such as unauthorized service requests and denial of service, due to weaknesses in the third-party portal's security, which can lead to undue invoicing or service cancellations.

Innovation Solution

A method of mutual authentication is implemented, where the user terminal transmits signed information to the remote server through the portal, allowing the server to authenticate the security element, and if recognized, the server responds with a signed value that the security element verifies, ensuring secure connection establishment and service execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a third-party portal is used to mediate communication between the terminal and remote server, then the ease of operation and service accessibility are improved, but the security vulnerability increases due to potential attacks on the portal

Engineering Contradiction:
Improveservice accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security element (UICC/eUICC) as an intermediary authentication component that mediates between the terminal and remote server. This security element verifies the terminal's identity and establishes secure credentials before the terminal can access services through the third-party portal, thereby maintaining ease of operation while enhancing security against portal attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication actions where the security element validates the terminal and establishes secure credentials (such as TLS-PSK keys) before the actual service request is made through the third-party portal. This preliminary security establishment prevents unauthorized access even if the portal is compromised during service execution

Inventive Principle:
Principle #10Preliminary action

2Reliability

If direct communication between terminal and remote server is established, then the security is improved by eliminating third-party vulnerabilities, but the ease of operation deteriorates due to complex authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security element (UICC/eUICC) performs self-service authentication by automatically verifying the terminal's identity and generating secure credentials without requiring user intervention for complex cryptographic operations. The terminal simply presents itself, and the security element handles the secure authentication process, maintaining ease of operation while ensuring direct secure communication with the remote server

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the terminal transmits service requests through the portal without authentication, then the ease of operation is improved, but the harmful factors increase due to unauthorized service requests and denial of service attacks

Engineering Contradiction:
Improveservice request simplicityVSAvoidunauthorized service requests
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by having the security element preemptively authenticate the terminal and establish secure credentials before any service request is transmitted through the third-party portal. This preliminary security measure prevents unauthorized service requests and denial of service attacks by ensuring that only authenticated terminals can access services, while maintaining simple operation for legitimate users

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2912818B1Method for mutual authentication between a terminal and a remote server via a third-party portal
Publication Date: 2017.05.03 THALES DIS FRANCE SA
  • EP2912818B1 patent drawingFigure 1~2
  • EP2912818B1 patent drawingFigure 3~4
  • EP2912818B1 patent drawing

AI summary

The invention relates to a method for mutual authentication between: (i) a user terminal (10) cooperating with a security element (11) as well as an application (12) for registering with a service, and (ii) a remote server (13), by means of a third-party portal (14), the remote server (13) being suitable for providing the service. According to the invention, the method consists in: i) after authenticating the user of the user terminal (10) with the portal (14), transmitting, to the remote server (13) by means of the portal (14), signed information R enabling the security element (11), as well as a service request, to be authenticated in the remote server (13); ii) authenticating the security element (11) in the remote server (13) and, if the security element (11) is recognized, iii) transmitting a value R' signed by the remote server (13) from the remote server (13) to the application (12) by means of the portal (14), the value R' including the information as well as a URL address making a response to the request possible; iv) transmitting a request for verification of the signed value R' from the application (12) to the security element (11); v) verifying, in the security element (11), the signature of the remote server (13) and whether the requested service has been granted by the remote server (13); vi) establishing a secure connection with the remote server (13) using the security element (11), and requesting that the service be executed.