User Terminal Authentication Using RAN Location Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multifactor authentication methods are vulnerable to impersonation attacks, as they rely on user device information that can be easily spoofed or cloned, lacking an additional layer of security.

Innovation Solution

The method utilizes a Radio Access Network (RAN) to generate location information of the user device, comparing it with the IP address-associated location of the user terminal for authentication, providing an additional layer of security by ensuring the device's actual location matches the expected location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user device information is used for authentication, then authentication process is simplified, but security is weakened due to vulnerability to spoofing and cloning

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces RAN-generated location information as an intermediary element that mediates between the user device and authentication server. This intermediary provides verifiable location data that cannot be easily spoofed, thereby enhancing security while maintaining authentication simplicity. The RAN acts as a trusted third party that generates authoritative location information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical/authentication-based location verification (relying on device-provided location data) with a network-based verification system. The RAN generates and provides location information directly to the authentication server, substituting the need for device-based location mechanisms that are vulnerable to spoofing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If RAN-generated location information is used for authentication, then security is enhanced by preventing impersonation, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The RAN autonomously generates location information and provides it to the authentication server without requiring additional user action or device complexity. The network infrastructure itself performs the verification function, eliminating the need for complex client-side authentication mechanisms while maintaining high security.

Inventive Principle:
Principle #25Self-service

3Reliability

If location comparison authentication is implemented, then impersonation attacks are resisted, but authentication time increases

Engineering Contradiction:
Improveimpersonation resistanceVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The RAN generates location information as part of the normal network communication process before authentication is required. This preliminary generation of location data eliminates the need for separate location verification steps during authentication, thereby resisting impersonation attacks without significantly increasing authentication time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260046618A1Method of authenticating a user terminal
Publication Date: 2026.02.12 VODAFONE PORTUGAL - COMUNICAÇÕES PESSOAIS SA
  • US20260046618A1 patent drawing
  • US20260046618A1 patent drawing
  • US20260046618A1 patent drawing

AI summary

A method of authenticating a user terminal having an associated IP address is provided. The method comprises trans-mitting an authentication message from an authentication server to a user device associated with the user terminal. The authentication message is transmitted to the user device at least in part over a Radio Access Network (RAN), wherein the RAN generates location information of the user device when transmitting the authentication message to the user device. The user terminal is authenticated based on a comparison of a location associated with the IP address of the user terminal and the location information of the user device.