SIM-Based Transaction Authentication via OTA Message Encapsulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing transaction authentication methods between data processing apparatus and third parties, especially over telecommunications networks, face challenges in securely and efficiently authenticating entities and facilitating transactions, particularly when payments are involved, due to the need for standardized message formats and secure data transmission across diverse network components.
Innovation Solution
The method involves using authentication storage means, such as a SIM, coupled with authenticating means via a communications network, transmitting data in a predetermined message format recognizable across network elements, which also handles non-authentication data, ensuring secure and standardized authentication processes for transactions and payments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If standardized message formats are used for authentication data transmission across diverse network components, then interoperability and compatibility are improved, but the complexity of securing and managing these standardized formats across multiple network elements increases
Solution Approach 1:
The patent applies universality by designing a message format that serves multiple functions: it can carry both authentication data and non-authentication data, and can be transmitted across different network elements (SMS gateway, mobile switching center, service center) without requiring format conversion. This single standardized format achieves interoperability across diverse telecommunications networks while avoiding the complexity of managing multiple specialized formats.
2Productivity
If authentication data is transmitted through multiple network elements using standardized formats, then transaction facilitation is improved, but the security risks and authentication challenges increase due to the plurality of transmission points
Solution Approach 1:
The patent employs an intermediary approach by introducing a standardized message format that acts as a secure container for authentication data as it passes through multiple network elements. The message format includes specific fields (such as command, parameter, and data fields) that maintain data integrity and confidentiality throughout the transmission chain, allowing the data to be facilitated across multiple points while preserving security through structured encapsulation.
3Ease of manufacture
If existing authentication methods are used without standardized message formats, then implementation simplicity is maintained, but compatibility and interoperability across different telecommunications networks deteriorate
Solution Approach 1:
The patent applies segmentation by dividing the authentication data into structured fields within the message format (command field, parameter field, data field, etc.). This segmentation allows each component to be handled independently by different network elements while maintaining overall compatibility. The segmented structure enables simple implementation at each node while achieving broad interoperability across diverse telecommunications networks.
Data Source
AI summary
A computer, such as a Windows-based PC 23, has associated with it a Subscriber Identity Module (SIM) 15, such as of the type used in a GSM or UMTS cellular or mobile telecommunications network. The SIM 15 can be authenticated with the network 3 in the same way as for authenticating SIMs of mobile telephone handsets used in the network, and can in this way authenticate the user of the PC 23 or the PC 23 itself. Such authentication can, for example, permit use of the PC 23 in relation to a particular application running on the PC 23. Challenge and response messages are transmitted between the network 3 and the SIM 15 via an authenticator module 30 implemented on the PC 23. These authentication messages have the predetermined format of an Over The Air (OTA) message, which is also used in GSM or UMTS telecommunications networks to transmit non-authentication messages—for example, SMS messages. The authentication data is encapsulated within OTA messages. The OTA messages are not necessarily transmitted wirelessly (that is, over the air). They may be transmitted via a fixed network; however, they have the predetermined format of OTA messages.


