Challenge-Response SIM Authentication for Local Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods in local communication networks, such as home networks, require manual user input and are not scalable for secure device authentication, and existing SIM-based authentication processes are limited to cellular networks, lacking flexibility for use in other network types.
Innovation Solution
A method utilizing a challenge-response mechanism where a first communications device temporarily accesses a challenge-response means, stores a challenge-response pair, and then uses this pair to authenticate a second device, allowing for flexible authentication in various network environments without manual user input.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If manual user input of identification data is used for authentication in local networks, then authentication can be performed, but the process is not scalable and requires manual user input
Solution Approach 1:
The system enables devices to authenticate each other automatically without manual user input. The first device stores challenge-response pairs generated from challenges sent by the second device, and subsequently uses these stored pairs to authenticate the second device automatically, eliminating the need for manual authentication operations.
Solution Approach 2:
The system performs preliminary actions by having the first device store challenge-response pairs in advance during an initial interaction. These pre-stored pairs are then used for subsequent automatic authentication, allowing the system to prepare authentication credentials before the actual authentication event occurs.
2Adaptability or versatility
If SIM-based authentication is used in cellular networks, then secure authentication is achieved, but the process is limited to cellular networks and lacks flexibility
Solution Approach 1:
The patent makes SIM-based authentication universal by enabling the same challenge-response mechanism to function in both cellular networks and local networks. The first device can store challenge-response pairs from cellular network authentication and reuse them for local network authentication, allowing a single mechanism to serve multiple network types.
Solution Approach 2:
The challenge-response means acts as an intermediary that bridges different network types. By storing challenge-response pairs generated from cellular network authentication and making them available for local network authentication, the system creates a universal authentication layer that works across different network environments.
3Productivity
If challenge-response pairs are stored and reused for authentication, then authentication scalability is improved, but the complexity of managing stored pairs increases
Solution Approach 1:
The system uses copying by having the first device store copies of challenge-response pairs generated during initial interactions. These copied pairs are then reused for subsequent authentication events, eliminating the need to regenerate authentication data each time and simplifying the authentication process.
Solution Approach 2:
The system discards the complexity of generating new authentication pairs each time by recovering and reusing previously generated challenge-response pairs. The first device retrieves stored pairs from memory and reuses them for authentication, eliminating the need to manage complex real-time pair generation and reducing overall system complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A process is provided in which a first device, e.g. a hub device (2) of a home network (1), is temporarily provided with a SIM (20) to store a challenge-response, and thereafter the first device (2) uses the stored challenge-response to interrogate a second device e.g. a mobile telephone (2), to authenticate that the second device (12) now has the SIM (20) that the first device (2) was previously provided with. A further process is provided in which the second device (12) authenticates that the first device (2) previously had access to the SIM (20) by verifying that a response from one or more challenge-response pairs provided by the first device (2) to the second device (12) is the same as a response received by the second device (12) from the SIM (20) when the second device (12) interrogates the SIM (20) with the challenge of the challenge-response pair received earlier from the first device (2).