Wireless Authentication via SMS Credential Relay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless authentication methods, such as web-based login and SMS-based token systems, are cumbersome and vulnerable to security threats, requiring manual user interaction and potentially exposing credentials to hijacking due to the transmission of plain text passwords.

Innovation Solution

A client-server based communication system that automates user authentication by detecting authentication events at a wireless communication device, obtaining credentials from a second wireless network, and establishing a connection to a first wireless network through an access point, using SMS messages or signaling sessions to simplify and secure the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If web-based login is used for authentication, then ease of operation is improved, but security deteriorates due to plain text password transmission

Engineering Contradiction:
Improveauthentication processVSAvoidcredential hijacking
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication server that mediates between the user and the network. Instead of transmitting passwords directly, the system uses an authentication server to verify credentials through SMS-based one-time passwords or token-based authentication, eliminating plain text password transmission while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical system of manual password entry and transmission with an automated SMS-based authentication system. The authentication server automatically sends one-time passwords via SMS and processes authentication without requiring users to manually transmit passwords, thereby eliminating security vulnerabilities while maintaining ease of use.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Object-affected harmful factors

If SMS-based token authentication is used, then security is improved, but device complexity increases

Engineering Contradiction:
Improvepassword securityVSAvoidauthentication system
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication system that can handle multiple authentication methods (SMS-based one-time passwords, token-based authentication, and web-based login) through a single authentication server. This multi-functional approach provides enhanced security while maintaining system simplicity by consolidating multiple authentication mechanisms into one unified platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system operates autonomously without requiring complex user configuration. The server automatically sends SMS messages, generates one-time passwords, validates credentials, and manages authentication sessions. This self-service capability reduces the perceived complexity for users while providing robust security through automated cryptographic processes.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If manual authentication steps are required, then security is improved, but productivity deteriorates due to time-consuming processes

Engineering Contradiction:
Improvecredential protectionVSAvoidauthentication speed
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the authentication server with user credentials and authentication policies before actual authentication events. The system prepares authentication mechanisms in advance, so when a user needs authentication, the process is already optimized and ready to execute rapidly. SMS messages and one-time passwords are generated and transmitted immediately without requiring complex real-time computations, thus protecting credentials while maintaining high speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8677125B2Authenticating a user of a communication device to a wireless network to which the user is not associated with
Publication Date: 2014.03.18 ALCATEL LUCENT SA
  • US8677125B2 patent drawing
  • US8677125B2 patent drawing
  • US8677125B2 patent drawing

AI summary

The present invention provides a method and an apparatus for automating authentication of a user. In one embodiment, a method calls for detecting an authentication event at a wireless communication device to gain access to a first wireless network through an access point associated with the first wireless network, automatically obtaining a credential from a second wireless network in response to the authentication event, and authenticating the user based on the credential to establish a connection between the wireless communication device and the first wireless network. A client-server based communication system includes a client module at a wireless communication device for user authentication of a Wi-Fi device to a Wi-Fi network through an access point associated therewith. For the purposes of authentication, the client-server based communication system further includes a server module with which the client module may automatically exchange short message service messages over a wide area network.