Authentication System for Recycled Telephone Numbers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The use of communications account identifiers (CAIs) for authentication is susceptible to recyclable CAI vulnerability, where a reused CAI can allow unauthorized access to accounts, as these identifiers can be reassigned to new users, compromising security without requiring complex password management.

Innovation Solution

A CAI security system performs a secondary authentication when the recyclable CAI criterion is satisfied, using information independent of the primary authentication, such as maiden name or device-specific data, to ensure only the original account holder gains access, thereby preventing unauthorized access due to CAI recycling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a communications account identifier (CAI) is used for authentication, then ease of operation is improved, but security deteriorates due to recyclable CAI vulnerability

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs a preliminary check to determine whether a CAI is recyclable before completing authentication. This preliminary action identifies potential security risks in advance, allowing the system to apply additional verification only when necessary, thus maintaining simplicity for non-recyclable CAIs while securing against recyclable CAI vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process dynamically adapts based on the recyclability status of the CAI. When a CAI is determined to be recyclable, the system activates additional verification steps; when not recyclable, the standard simple authentication proceeds. This dynamic adjustment resolves the contradiction by making the system simple when safe and secure when risky.

Inventive Principle:
Principle #15Dynamics

2Reliability

If secondary authentication is performed for recyclable CAIs, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct components: a CAI recyclability determination module, a primary authentication module, and a secondary verification module. This segmentation allows the system to activate only the necessary components based on CAI recyclability, reducing overall complexity while maintaining security for recyclable CAIs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the recyclability determination system) that sits between the CAI and the authentication process. This intermediary assesses whether additional verification is needed, allowing the system to maintain simplicity for most cases while providing enhanced security pathways when required, thus managing complexity effectively.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If CAI recycling is allowed, then adaptability is improved, but security deteriorates due to unauthorized access

Engineering Contradiction:
ImproveCAI reassignment flexibilityVSAvoidaccount access security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system applies preliminary anti-action by implementing verification measures that prevent unauthorized access resulting from CAI recycling. Before allowing access based on a recycled CAI, the system proactively checks for recyclability and applies additional verification, countering the security risk before it can manifest as unauthorized access.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The authentication system incorporates feedback mechanisms that monitor CAI usage patterns and recyclability status. When a CAI is identified as recyclable, the system provides feedback by activating enhanced verification protocols. This feedback loop maintains security while allowing CAI recycling to proceed, balancing adaptability with security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3491564B1Authentication based on telephone number recycling
Publication Date: 2021.06.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3491564B1 patent drawingFigure 1
  • EP3491564B1 patent drawingFigure 2
  • EP3491564B1 patent drawingFigure 3

AI summary

A method and system for authenticating a user is provided. In some embodiments, a security system determines whether the time since the last authentication was successful is less than a recycle telephone number period (e.g., the minimum time before which a telephone number might be assigned to a new user). If the time is less than the recycle telephone number period, the security system performs a primary authentication of the user based on a telephone number received from the user. When the primary authentication is successful, the security system indicates that the user has been authenticated. When the time is not less than a recycle telephone number period, the security system performs a secondary authentication of the user. When the secondary authentication is successful, the security system indicates that the user has been authenticated.