Single Sign-On Identity Authenticator Using Mobile Network Operator Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on (SSO) technologies face limitations in providing comprehensive security, as they often rely solely on user identification and require users to manage multiple registrations, leading to security downgrades and limited expandability due to the need for known identity authenticator addresses.
Innovation Solution
A SSO authentication system comprising a service provider node, an identity authenticator, and a user terminal, where the identity authenticator verifies user identifiers and provides verification information, using a secure association built after device authentication with a mobile network operator, and an authenticator registry to manage network addresses of identity authenticators, allowing for dynamic association and additional security measures like one-time passwords.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional SSO systems use third-party identity providers (e.g., Google, Facebook), then user identification is provided, but service providers do not trust these providers for verifying sensitive transactions (e.g., bank transactions)
Solution Approach 1:
The patent introduces a mobile network operator as an intermediary identity authenticator between users and service providers. The mobile network operator's authentication component verifies user identities using SIM card-based authentication, providing a trusted intermediary that both users and service providers can rely on for secure transactions while maintaining service provider independence.
2Reliability
If the address of the identity authenticator is known by every service provider, then verification can be performed, but the expandability of the SSO framework is severely limited
Solution Approach 1:
The patent makes the mobile network operator's authentication component a universal identity authenticator that can serve multiple service providers without requiring each provider to know its address. The authentication component can be reached via the mobile network infrastructure, allowing any service provider to verify user identities through the mobile network operator's network without direct address knowledge.
3Ease of operation
If users reuse the same username/password combination for each registration to avoid remembering multiple combinations, then ease of use is improved, but the overall security of service registrations is downgraded
Solution Approach 1:
The patent enables users to authenticate themselves across multiple services using their mobile device's built-in authentication capabilities (SIM card, device identifiers). The mobile network operator's authentication component verifies user identities through the user's own device, eliminating the need for users to manage multiple passwords while maintaining high security through device-based authentication.
Data Source
Figure 1~3
Figure 4A
Figure 4B
AI summary
The present disclosure generally relates to user and device Authentication. More specifically, the present disclosure relates to a technique of single sign-on (SSO) authentication. An apparatus embodiment of a single sign-on (SSO) authentication system comprises a service provider node configured to provide access to at least one service over a network; an identity authenticator accessible over the network; a user terminal including an authentication component configured to build a secure association with the identity authenticator; and a user agent configured to access the service provider node to request a service of the provided at least one service. The service provider node is further configured to request a user identifier from a user and to request the identity authenticator for verification of a given user identifier. The identity authenticator is further configured to connect to the authentication component of the user terminal to verify the user identifier and to provide the service provider node with verification information indicating the verification of the given user identifier. A corresponding identity authenticator, user terminal and method are also provided.