Secondary Authentication via Terminal Identity Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In secondary authentication processes, there is a risk of user identity leakage during the transmission of user identities from terminal devices to third-party networks, compromising security.

Innovation Solution

The core network function entity sends the identity of the terminal device to the authentication device in an out-of-band manner, allowing the authentication device to determine the user's identity based on a mapping relationship, thereby reducing direct exposure of the user's identity and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the core network function entity directly sends the user identity to the authentication device in the second network, then the authentication process can be completed, but the user identity may be leaked during transmission

Engineering Contradiction:
Improvesecurity protection of user identityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces the terminal device's original identity (e.g., IMEI, IMSI) as an intermediary to indirectly represent the user identity. Instead of directly transmitting the user identity (e.g., username, account ID), the system sends the terminal's identity which the authentication device then maps to the corresponding user identity through pre-established mapping relationships. This intermediary approach protects the actual user identity from direct exposure during transmission while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses a mapping relationship mechanism where the authentication device maintains a correspondence table between terminal identities and user identities. The terminal's identity serves as a copy or proxy that represents the user identity without being the actual user identity itself. This copying approach allows the system to work with safer, less sensitive identity data during transmission while still being able to identify and authenticate the correct user through the mapping relationship.

Inventive Principle:
Principle #26Copying

2Productivity

If the core network function entity requests user identity from the terminal device through standard procedures, then the authentication can proceed, but it increases signaling overhead and reduces efficiency

Engineering Contradiction:
Improvesignaling efficiencyVSAvoidnetwork resource waste
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent establishes mapping relationships between terminal identities and user identities in advance, before the authentication process begins. The authentication device pre-configures correspondence tables that link terminal identifiers (IMEI, IMSI) with user identifiers (username, account ID). This preliminary action eliminates the need for real-time identity requests and mappings during the authentication signaling process, thereby reducing signaling overhead and improving efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the identity request step from the standard authentication signaling procedure. Instead of following the conventional path where the network requests user identity from the terminal during authentication, the system removes this unnecessary step by directly utilizing the terminal's original identity that is already available in the authentication request. This extraction eliminates redundant signaling messages and optimizes the authentication flow.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12513142B2Secondary authentication method and apparatus
Publication Date: 2025.12.30 HUAWEI TECH CO LTD
  • US12513142B2 patent drawing
  • US12513142B2 patent drawing
  • US12513142B2 patent drawing

AI summary

The present disclosure relates to secondary authentication methods and apparatus. In one example method, a core network function entity obtains an identity of a first terminal device, where the identity of the first terminal device is an identity in a first network. The core network function entity sends the identity of the first terminal device to an authentication device in a second network, where the identity of the first terminal device is used to determine an identity used by the second network to perform secondary authentication on a first user, and the identity of the first user is different from the identity of the first terminal device.