SIM-Based Mobile App Authentication Without SMS Code Entry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SMS-based multi-factor authentication (MFA) methods in cellular networks are cumbersome, insecure, and prone to interception, compromising user security and experience.
Innovation Solution
Implement a SIM-based authentication method using a mobile device's operating system and mobile network operator (MNO) infrastructure for multi-factor authentication, leveraging a subscriber identity module (SIM) to provide a secure and reliable authentication process through a SIM-based extensible authentication protocol (EAP-AKA) message exchange, eliminating the need for manual entry of one-time codes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM-based authentication with EAP-AKA message exchange is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where the SIM card and EAP-AKA protocol act as mediators between the user device and the application server. The SIM card stores authentication credentials and performs cryptographic operations, while the EAP-AKA protocol provides a standardized message exchange framework. This intermediary layer enhances security without requiring complex changes to the application or device software.
Solution Approach 2:
The patent utilizes the existing SIM card authentication infrastructure and copies its security model to application-level authentication. By reusing the SIM card's stored credentials and the EAP-AKA protocol already established for network authentication, the system avoids creating new complex authentication mechanisms while achieving comparable or enhanced security.
2Ease of operation
If manual entry of one-time codes is eliminated, then ease of operation is improved, but reliability may worsen due to automated interception risks
Solution Approach 1:
The patent replaces the mechanical process of manual one-time code entry with an automated cryptographic authentication mechanism. Instead of users receiving SMS codes and manually entering them, the system uses the SIM card to perform automated cryptographic operations through the EAP-AKA protocol, substituting the manual mechanical process with an automated electronic authentication system that is more secure and user-friendly.
3Reliability
If short-life tokens are generated by MNO infrastructure, then security is improved, but loss of time increases during authentication
Solution Approach 1:
The patent implements preliminary action by pre-provisioning authentication credentials in the SIM card before they are needed. The SIM card already contains cryptographic keys and authentication data, so when authentication is required, the system can immediately use these pre-prepared credentials without needing to generate or transmit additional security data, reducing authentication time while maintaining security.
Data Source
AI summary
An operating system provided by a processing system including at least one processor of a cellular endpoint device may obtain an authentication request from an application of a third party application provider and may transmit an entitlement request to a cellular network in accordance with a subscriber identity module-based authentication message exchange, in response to the authentication request. The operating system may then obtain an authorization indicator from the cellular network, in accordance with the subscriber identity module-based authentication message exchange, and may provide an authentication confirmation to the application in response to the obtaining of the authorization indicator.


