Telecom Operator Intermediary for Secure Mobile Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods using a mobile phone number as a second factor for Internet-based business applications are vulnerable to privacy issues, fraud, and security risks, as they require users to disclose their phone number, are susceptible to number changes and theft, and do not adequately protect user security.

Innovation Solution

The telecom operator is responsible for managing the user's mobile phone number, with the business application sending the authentication token to the telecom operator instead of the user, allowing for secure forwarding to the user's terminal without revealing the phone number, optimizing communication, and ensuring mutual authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the business application sends the token directly to the user's mobile phone number, then the authentication process is simple and direct, but the user's privacy is compromised and the phone number may be misused

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidprivacy exposure and fraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a telecom operator as an intermediary between the business application and the user's mobile device. The business application sends the token to the telecom operator, which then forwards it to the user's registered device. This mediator approach allows authentication to proceed without the business application directly handling the user's phone number, thus protecting privacy while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If the user's mobile phone number is stored and used for token delivery, then timely authentication is possible, but the number may be changed or stolen leading to security issues

Engineering Contradiction:
Improvetoken delivery speedVSAvoidauthentication security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The telecom operator acts as a trusted intermediary that manages the user's device information securely. The operator receives the token from the business application and delivers it to the user's current device without exposing the phone number to the application. This separation ensures that even if the application is compromised, the phone number remains protected, and the operator can verify the legitimacy of token requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary registration where the user associates their device with the telecom operator before actual authentication occurs. This pre-established trust relationship allows the operator to quickly and securely deliver tokens to the correct device without exposing sensitive information, ensuring both speed and reliability.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If the business application handles token delivery directly, then the communication path is short and fast, but the application must store and manage sensitive user information

Engineering Contradiction:
Improvecommunication timeVSAvoidinformation management complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The telecom operator serves as a specialized intermediary that handles all sensitive information management tasks. The business application only needs to communicate with the operator through standardized interfaces, significantly reducing its complexity. The operator, being a trusted entity with existing user relationships, can efficiently manage device information and deliver tokens without exposing sensitive data to multiple applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of manufacture

If the user provides phone number to the business application, then token delivery can be implemented, but the application may resell or misuse the number

Engineering Contradiction:
Improveauthentication implementationVSAvoiddata misuse and resale
Core Design Contradiction:
Ease of manufactureVSObject-generated harmful factors

Solution Approach 1:

The telecom operator acts as a protective intermediary that never exposes the user's phone number to the business application. The application communicates only with the operator, which handles all interactions with the user's device. This architecture makes it impossible for the application to obtain or misuse the phone number, as the operator controls and protects this sensitive information while still enabling authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP1995927B1Method, forwarding device and modules for authentication of a user at a business application over the internet
Publication Date: 2015.10.21 ALCATEL LUCENT SA
  • EP1995927B1 patent drawing

AI summary

The invention relates to a method, a forwarding device (FWS), a forwarding module (FWM) and a business application module (BAM) for authentication of a user (U1, U2) at a business application (BA) over the Internet (INT), wherein a token (TK1, TK2) is transmitted from said business application (BA) to a communication terminal of said user (U1, U2), said communication terminal being connected to a telecommunications network (TN), and wherein said user (U1, U2) sends said token or a token information deduced from said token (TK1, TK2) to said business application (BA) for authentication at said business application (BA). Said business application (BA) sends said token in connection with a user identifier (UI1, UI2) identifying said user (U1, U2) to a forwarding device (FWS) of said telecommunications network (TN). Said forwarding device (FWS) determines a communication address (CA1, CA2) of said communication terminal by means of said user identifier (UI1, UI2) and said forwarding device (FWS) forwards said token to said communication terminal by means of said communication address (CA1, CA2).