SIM-Based Mobile App Authentication Without SMS Code Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SMS-based multi-factor authentication (MFA) methods in cellular networks are cumbersome, insecure, and prone to interception, compromising user security and experience.

Innovation Solution

Implement a SIM-based authentication method using a mobile device's operating system and mobile network operator (MNO) infrastructure for multi-factor authentication, leveraging a subscriber identity module (SIM) to provide a secure and reliable authentication process through a SIM-based extensible authentication protocol (EAP-AKA) message exchange, eliminating the need for manual entry of one-time codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM-based authentication with EAP-AKA message exchange is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where the SIM card and EAP-AKA protocol act as mediators between the user device and the application server. The SIM card stores authentication credentials and performs cryptographic operations, while the EAP-AKA protocol provides a standardized message exchange framework. This intermediary layer enhances security without requiring complex changes to the application or device software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent utilizes the existing SIM card authentication infrastructure and copies its security model to application-level authentication. By reusing the SIM card's stored credentials and the EAP-AKA protocol already established for network authentication, the system avoids creating new complex authentication mechanisms while achieving comparable or enhanced security.

Inventive Principle:
Principle #26Copying

2Ease of operation

If manual entry of one-time codes is eliminated, then ease of operation is improved, but reliability may worsen due to automated interception risks

Engineering Contradiction:
Improveuser intervention requirementVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical process of manual one-time code entry with an automated cryptographic authentication mechanism. Instead of users receiving SMS codes and manually entering them, the system uses the SIM card to perform automated cryptographic operations through the EAP-AKA protocol, substituting the manual mechanical process with an automated electronic authentication system that is more secure and user-friendly.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If short-life tokens are generated by MNO infrastructure, then security is improved, but loss of time increases during authentication

Engineering Contradiction:
Improvetoken securityVSAvoidauthentication duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-provisioning authentication credentials in the SIM card before they are needed. The SIM card already contains cryptographic keys and authentication data, so when authentication is required, the system can immediately use these pre-prepared credentials without needing to generate or transmit additional security data, reducing authentication time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12520138B2Subscriber identity module-based authentication for mobile applications
Publication Date: 2026.01.06 AT&T INTELLECTUAL PROPERTY I L P
  • US12520138B2 patent drawing
  • US12520138B2 patent drawing
  • US12520138B2 patent drawing

AI summary

An operating system provided by a processing system including at least one processor of a cellular endpoint device may obtain an authentication request from an application of a third party application provider and may transmit an entitlement request to a cellular network in accordance with a subscriber identity module-based authentication message exchange, in response to the authentication request. The operating system may then obtain an authorization indicator from the cellular network, in accordance with the subscriber identity module-based authentication message exchange, and may provide an authentication confirmation to the application in response to the obtaining of the authorization indicator.