SIM-Based FIDO Authentication via Challenge Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for user authentication at online service providers, such as text messages, authentication apps, and physical devices, face security concerns, convenience issues, and accessibility limitations.
Innovation Solution
A SIM-based sign-on authentication service that uses a subscriber identity module (SIM) to generate and encrypt a challenge response, sent over-the-air (OTA) to an identity provider for verification, allowing secure and convenient user authentication without the need for additional hardware or apps.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If text messaging service is used to send challenge questions, then convenience is improved since it can be sent to nearly any mobile device, but security deteriorates as the text message may be intercepted in transit
Solution Approach 1:
The patent introduces an authentication app as an intermediary component that securely handles challenge questions and responses. Instead of sending challenges directly via SMS, the system uses the authentication app to generate, display, and verify responses, creating a secure intermediary layer that prevents interception while maintaining mobile device accessibility
Solution Approach 2:
The patent replaces the insecure SMS text messaging system with a software-based authentication application. This substitution eliminates the vulnerability of text messages being intercepted in transit, as the authentication app communicates through secure application-to-application channels rather than through vulnerable text message protocols
2Reliability
If authentication app is used, then security is improved but device complexity increases since the user may need to install the app for each device
Solution Approach 1:
The patent makes the authentication app universal by enabling it to be installed once on a user's mobile device and automatically accessible across multiple devices and services. The app serves multiple authentication functions across different online service providers without requiring separate installations, reducing overall device complexity while maintaining security
Solution Approach 2:
The patent performs preliminary setup by having the user install and configure the authentication app once during initial device setup. This preliminary action establishes the authentication mechanism in advance, so that subsequent authentications across different devices and services can proceed without additional installation steps, reducing complexity for future use
3Reliability
If physical authentication device is used, then security is improved since user must physically carry it, but ease of operation deteriorates as user must remember to carry it and it may be inaccessible on mobile devices
Solution Approach 1:
The patent replaces the physical authentication device (such as a USB key or smart card) with a software-based authentication application on the mobile device. This substitution eliminates the need for separate physical hardware while maintaining security through cryptographic operations performed by the authentication app, and improves accessibility by integrating authentication directly into the device already carried by the user
Solution Approach 2:
The patent merges the authentication function with the mobile device itself by installing the authentication app on the device the user already carries. This combination eliminates the need to carry separate physical authentication devices, as the mobile device integrates both communication capabilities and authentication functionality in a single unified system
Data Source
AI summary
Systems and techniques for authenticating user sign-on at an online service provider using a subscriber identity module (SIM) based authentication process are discussed herein. A user may request to sign-on an online service provider using a user device. The user device may be requested to provide a response to a challenge sent by the online service provider. The online service provider may interface with an identity provider (IDP) to send the challenge. The challenge may be received at a SIM component associated with the user device. The SIM component may generate a challenge response to the challenge, encrypt the response with a first security key associated with the SIM component, and send the encrypted challenge response to the IDP using the OTA component. The IDP may authenticate the encrypted challenge response using a second security key associated with the IDP.


