Challenge-Response SIM Authentication for Local Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods in local communication networks, such as home networks, require manual user input and are not scalable for secure device authentication, and existing SIM-based authentication processes are limited to cellular networks, lacking flexibility for use in other network types.

Innovation Solution

A method utilizing a challenge-response mechanism where a first communications device temporarily accesses a challenge-response means, stores a challenge-response pair, and then uses this pair to authenticate a second device, allowing for flexible authentication in various network environments without manual user input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If manual user input of identification data is used for authentication in local networks, then authentication can be performed, but the process is not scalable and requires manual user input

Engineering Contradiction:
Improveauthentication automationVSAvoidmanual user input requirement
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The system enables devices to authenticate each other automatically without manual user input. The first device stores challenge-response pairs generated from challenges sent by the second device, and subsequently uses these stored pairs to authenticate the second device automatically, eliminating the need for manual authentication operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by having the first device store challenge-response pairs in advance during an initial interaction. These pre-stored pairs are then used for subsequent automatic authentication, allowing the system to prepare authentication credentials before the actual authentication event occurs.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If SIM-based authentication is used in cellular networks, then secure authentication is achieved, but the process is limited to cellular networks and lacks flexibility

Engineering Contradiction:
Improvenetwork type flexibilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent makes SIM-based authentication universal by enabling the same challenge-response mechanism to function in both cellular networks and local networks. The first device can store challenge-response pairs from cellular network authentication and reuse them for local network authentication, allowing a single mechanism to serve multiple network types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The challenge-response means acts as an intermediary that bridges different network types. By storing challenge-response pairs generated from cellular network authentication and making them available for local network authentication, the system creates a universal authentication layer that works across different network environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If challenge-response pairs are stored and reused for authentication, then authentication scalability is improved, but the complexity of managing stored pairs increases

Engineering Contradiction:
Improveauthentication scalabilityVSAvoidchallenge-response pair management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system uses copying by having the first device store copies of challenge-response pairs generated during initial interactions. These copied pairs are then reused for subsequent authentication events, eliminating the need to regenerate authentication data each time and simplifying the authentication process.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system discards the complexity of generating new authentication pairs each time by recovering and reusing previously generated challenge-response pairs. The first device retrieves stored pairs from memory and reuses them for authentication, eliminating the need to manage complex real-time pair generation and reducing overall system complexity.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentEP2014046B1Methods, apparatuses and storage medium for authentication of devices temporarily provided with a SIM card to store a challenge-response
Publication Date: 2016.03.02 BRITISH TELECOM PLC
  • EP2014046B1 patent drawingFigure 1
  • EP2014046B1 patent drawingFigure 2
  • EP2014046B1 patent drawingFigure 3

AI summary

A process is provided in which a first device, e.g. a hub device (2) of a home network (1), is temporarily provided with a SIM (20) to store a challenge-response, and thereafter the first device (2) uses the stored challenge-response to interrogate a second device e.g. a mobile telephone (2), to authenticate that the second device (12) now has the SIM (20) that the first device (2) was previously provided with. A further process is provided in which the second device (12) authenticates that the first device (2) previously had access to the SIM (20) by verifying that a response from one or more challenge-response pairs provided by the first device (2) to the second device (12) is the same as a response received by the second device (12) from the SIM (20) when the second device (12) interrogates the SIM (20) with the challenge of the challenge-response pair received earlier from the first device (2).