User Terminal Authentication Using RAN Location Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multifactor authentication methods are vulnerable to impersonation attacks, as they rely on user device information that can be easily spoofed or cloned, lacking an additional layer of security.
Innovation Solution
The method utilizes a Radio Access Network (RAN) to generate location information of the user device, comparing it with the IP address-associated location of the user terminal for authentication, providing an additional layer of security by ensuring the device's actual location matches the expected location.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user device information is used for authentication, then authentication process is simplified, but security is weakened due to vulnerability to spoofing and cloning
Solution Approach 1:
The patent introduces RAN-generated location information as an intermediary element that mediates between the user device and authentication server. This intermediary provides verifiable location data that cannot be easily spoofed, thereby enhancing security while maintaining authentication simplicity. The RAN acts as a trusted third party that generates authoritative location information.
Solution Approach 2:
The patent replaces traditional mechanical/authentication-based location verification (relying on device-provided location data) with a network-based verification system. The RAN generates and provides location information directly to the authentication server, substituting the need for device-based location mechanisms that are vulnerable to spoofing.
2Reliability
If RAN-generated location information is used for authentication, then security is enhanced by preventing impersonation, but device complexity increases
Solution Approach 1:
The RAN autonomously generates location information and provides it to the authentication server without requiring additional user action or device complexity. The network infrastructure itself performs the verification function, eliminating the need for complex client-side authentication mechanisms while maintaining high security.
3Reliability
If location comparison authentication is implemented, then impersonation attacks are resisted, but authentication time increases
Solution Approach 1:
The RAN generates location information as part of the normal network communication process before authentication is required. This preliminary generation of location data eliminates the need for separate location verification steps during authentication, thereby resisting impersonation attacks without significantly increasing authentication time.
Data Source
AI summary
A method of authenticating a user terminal having an associated IP address is provided. The method comprises trans-mitting an authentication message from an authentication server to a user device associated with the user terminal. The authentication message is transmitted to the user device at least in part over a Radio Access Network (RAN), wherein the RAN generates location information of the user device when transmitting the authentication message to the user device. The user terminal is authenticated based on a comparison of a location associated with the IP address of the user terminal and the location information of the user device.


