Server Trust Evaluation for Wireless Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional authentication methods for subscriber identity modules (SIMs) in wireless devices are susceptible to misuse, as they rely on physical possession, which does not guarantee rightful ownership, and require carrier user login credentials that are often forgotten, leading to sub-optimal user experiences and security vulnerabilities.

Innovation Solution

Implement a password-less secure authentication system that uses a trust evaluation by a server to determine if a user login is necessary, based on a user's history and device associations, allowing authentication tokens to be generated and verified, thereby enabling secure transactions without requiring frequent or forgotten login credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If carrier user login credentials are required for authentication, then security against SIM theft is improved, but user experience deteriorates due to forgotten passwords and authentication friction

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a remote server as an intermediary that performs trust evaluation between the mobile device and the carrier network. This intermediary assesses multiple trust factors (device integrity, user behavior, historical data) and returns a trust score that determines whether carrier login is required. This mediator resolves the contradiction by providing automated security assessment that protects against SIM theft while eliminating the need for user passwords in trusted scenarios.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes the authentication parameter from a static password requirement to a dynamic trust score threshold. The trust score is calculated based on multiple parameters including device integrity, user behavior patterns, and historical authentication data. By changing from a fixed credential-based parameter to a dynamic risk-based parameter, the system adapts authentication requirements to actual security needs, improving both security and user experience.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If SIM authentication is based on physical possession, then ease of operation is improved, but security vulnerability increases due to SIM theft and misuse

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary trust evaluation before allowing SIM-based authentication to proceed. The remote server assesses multiple trust factors in advance, including device integrity checks, user behavior analysis, and historical authentication patterns. This preliminary action determines whether the device should be granted access without carrier login, thereby maintaining ease of operation for legitimate users while preventing SIM theft attacks before they can succeed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback loops that continuously monitor device behavior, authentication patterns, and trust factors. The remote server receives ongoing feedback from the mobile device and carrier network, updates the trust score dynamically, and adjusts authentication requirements accordingly. This feedback mechanism allows the system to maintain ease of operation for trusted devices while automatically increasing security measures when suspicious activity is detected.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10917790B2Server trust evaluation based authentication
Publication Date: 2021.02.09 APPLE INC
  • US10917790B2 patent drawing
  • US10917790B2 patent drawing
  • US10917790B2 patent drawing

AI summary

Disclosed herein are techniques for enabling a user to activate a new device with a Mobile Network Operator (MNO) without requiring the user to provide MNO authentication credentials that are easily forgotten. The user activates the new device using credentials from an existing device (associated with the user) that is trusted by the MNO and also using a trust score provided by a third-party server that has knowledge of associations between the user and the existing device. The new device can be a supplemental device, such as a wearable device to a cellular phone, where both devices remain capable of accessing services provided by the MNO after the new device is activated with the MNO. The new device can also be a replacement device, such as a new phone, tablet, or wearable device, where the new device supplants access to services provided by the MNO for an existing device.