SIM-Based Mobile Authentication for Automatic Possession Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems require active user participation, creating inconvenience and introducing a weak security link, making them vulnerable to attacks and compromising security.
Innovation Solution
An authentication method that verifies user possession of a mobile device using the SIM identifier through a cryptographic challenge, eliminating the need for active user participation and enhancing security by leveraging the mobile data network's capability to identify the SIM.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If active authentication mechanisms (password, OTP, biometric) are used, then security verification is achieved, but user convenience deteriorates and a weak security link is introduced
Solution Approach 1:
The system performs authentication automatically without requiring active user participation. The mobile network operator's system autonomously verifies the user's possession of the mobile device by cryptographically validating the SIM card through the mobile data network, eliminating the need for user actions like entering passwords or presenting biometrics.
Solution Approach 2:
The mobile network operator's system acts as an intermediary between the user and the service provider. Instead of the user directly participating in authentication, the network operator's system mediates the process by verifying SIM card ownership through cryptographic challenges and comparing the verified identifier with the registered identifier.
2Reliability
If active authentication mechanisms are used, then identity verification is achieved, but security is weakened due to human vulnerability
Solution Approach 1:
The authentication process is automated and performed by the mobile network operator's system without human intervention. The system automatically conducts cryptographic verification of the SIM card and compares identifiers, eliminating the human element that introduces security vulnerabilities such as phishing susceptibility, OTP leakage, and biometric spoofing.
Solution Approach 2:
The patent replaces human-based authentication mechanisms with automated cryptographic verification. Instead of relying on human actions (entering passwords, presenting biometrics), the system uses cryptographic challenges and mathematical verification to authenticate device possession, substituting mechanical human processes with automated computational processes.
3Reliability
If OTP delivery methods (SMS, email, phone call) are used, then possession factor authentication is achieved, but security is compromised due to vulnerability to attacks
Solution Approach 1:
The patent replaces OTP delivery through vulnerable channels (SMS, email, phone calls) with direct cryptographic verification of the SIM card through the mobile data network. Instead of delivering a secret code that can be intercepted, the system performs cryptographic challenges directly with the SIM card and verifies the response, eliminating the vulnerable transmission channel.
Solution Approach 2:
The mobile network operator's system serves as a trusted intermediary that directly communicates with the SIM card through the secure mobile data network. This intermediary approach eliminates the need for OTP delivery through unsecured channels, as the verification process occurs directly between the network operator's system and the SIM card within the secure network infrastructure.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This method improves convenience and security by seamlessly verifying user possession without requiring active user input, reducing the risk of attacks and strengthening the authentication process.
Implementation Method 1
the mobile data network's capability to identify a mobile phone number using cryptography in the SIM
Data Source
Figure 1
Figure 2
Figure 3A~3C
AI summary
An authentication method for verifying that a user is in possession of a mobile device (12), the method comprising: generating a uniform resource locator, URL, in response to receiving a user identifier provided by a user at a mobile device (12) having a subscriber identity module, SIM; receiving the URL at the mobile device, the URL being configured to communicate with a network (14) associated with the SIM; retrieving, using the URL to access the network (14), a SIM identifier corresponding to the SIM; and verifying that the user is in possession of the mobile device (12) if the user identifier corresponds to the SIM identifier.