Mutual Authentication via Third-Party Portal Using Security Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for mutual authentication between a user terminal and a remote server via a third-party portal are vulnerable to security attacks, such as unauthorized service requests and denial of service, due to weaknesses in the third-party portal's security, which can lead to undue invoicing or service cancellations.
Innovation Solution
A method of mutual authentication is implemented, where the user terminal transmits signed information to the remote server through the portal, allowing the server to authenticate the security element, and if recognized, the server responds with a signed value that the security element verifies, ensuring secure connection establishment and service execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a third-party portal is used to mediate communication between the terminal and remote server, then the ease of operation and service accessibility are improved, but the security vulnerability increases due to potential attacks on the portal
Solution Approach 1:
The patent introduces a security element (UICC/eUICC) as an intermediary authentication component that mediates between the terminal and remote server. This security element verifies the terminal's identity and establishes secure credentials before the terminal can access services through the third-party portal, thereby maintaining ease of operation while enhancing security against portal attacks
Solution Approach 2:
The patent implements preliminary authentication actions where the security element validates the terminal and establishes secure credentials (such as TLS-PSK keys) before the actual service request is made through the third-party portal. This preliminary security establishment prevents unauthorized access even if the portal is compromised during service execution
2Reliability
If direct communication between terminal and remote server is established, then the security is improved by eliminating third-party vulnerabilities, but the ease of operation deteriorates due to complex authentication requirements
Solution Approach 1:
The security element (UICC/eUICC) performs self-service authentication by automatically verifying the terminal's identity and generating secure credentials without requiring user intervention for complex cryptographic operations. The terminal simply presents itself, and the security element handles the secure authentication process, maintaining ease of operation while ensuring direct secure communication with the remote server
3Ease of operation
If the terminal transmits service requests through the portal without authentication, then the ease of operation is improved, but the harmful factors increase due to unauthorized service requests and denial of service attacks
Solution Approach 1:
The patent applies preliminary anti-action by having the security element preemptively authenticate the terminal and establish secure credentials before any service request is transmitted through the third-party portal. This preliminary security measure prevents unauthorized service requests and denial of service attacks by ensuring that only authenticated terminals can access services, while maintaining simple operation for legitimate users
Data Source
Figure 1~2
Figure 3~4
AI summary
The invention relates to a method for mutual authentication between: (i) a user terminal (10) cooperating with a security element (11) as well as an application (12) for registering with a service, and (ii) a remote server (13), by means of a third-party portal (14), the remote server (13) being suitable for providing the service. According to the invention, the method consists in: i) after authenticating the user of the user terminal (10) with the portal (14), transmitting, to the remote server (13) by means of the portal (14), signed information R enabling the security element (11), as well as a service request, to be authenticated in the remote server (13); ii) authenticating the security element (11) in the remote server (13) and, if the security element (11) is recognized, iii) transmitting a value R' signed by the remote server (13) from the remote server (13) to the application (12) by means of the portal (14), the value R' including the information as well as a URL address making a response to the request possible; iv) transmitting a request for verification of the signed value R' from the application (12) to the security element (11); v) verifying, in the security element (11), the signature of the remote server (13) and whether the requested service has been granted by the remote server (13); vi) establishing a secure connection with the remote server (13) using the security element (11), and requesting that the service be executed.