Terminal Location Verification via Challenge-Response Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for verifying a customer's location within a mobile telephony network to apply special pricing are insecure, as users can manipulate location data, allowing unauthorized access to 'Home Zone' pricing.

Innovation Solution

A method involving a certification module that associates terminal identifiers with access point addresses, sending challenges, and verifying responses to ensure the terminal is at the correct location, with a secure correspondence table managed by the network and using a secret key for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the operator uses current location verification methods (mobile network coverage or access point identification), then the implementation is simple and low-cost, but the security is insufficient allowing users to manipulate location data for fraudulent access to special pricing

Engineering Contradiction:
Improvelocation verification securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing a secure correspondence table that links terminal identifiers to access point addresses before the actual location verification occurs. This table is created and stored securely in the network controller, enabling reliable verification without requiring complex real-time authentication protocols during the actual location check.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a certification module that acts as a mediator between the terminal and the network controller. This module verifies the terminal's location by checking the challenge-response authentication against the pre-established correspondence table, providing secure verification without requiring the network controller to directly handle complex authentication logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the operator implements a secure challenge-response verification system with certification modules, then the location verification security is improved, but the system complexity and implementation cost increase

Engineering Contradiction:
Improvelocation verification securityVSAvoidsystem implementation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent simplifies implementation by performing preliminary setup of the correspondence table during network configuration rather than requiring complex real-time authentication protocols. The table is pre-populated with terminal identifiers and their associated access point addresses, making the actual verification process straightforward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The certification module operates autonomously to verify terminal locations using the pre-established correspondence table. Once the table is set up, the system automatically performs challenge-response authentication without requiring manual intervention or complex configuration, making the system easy to operate once deployed.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP1867132B1Method and apparatuses for controlling presence of terminal on an access point to a telephone network
Publication Date: 2018.06.06 ORANGE SA
  • EP1867132B1 patent drawingFigure 1~2
  • EP1867132B1 patent drawingFigure 3

AI summary

The invention concerns a method for controlling the presence of a terminal (10) on an access point (31) to a first telephone network via a second communication network, said access point (31) being defined by an address in said second communication network. The invention is characterized in that said method includes the following steps: in an initializing phase, associating with said access point (31) a certification module (33); establishing a correspondence table between an identifier of said terminal (10) and said access point (31) address; then in a second controlling phase, requesting from the terminal (10) its identifier and deducing therefrom by means of said correspondence table the address of said access point (31) in the second network; sending, to said address, a challenge (RAND) so as to provide same to the associated certification module (33); determination by the certification module (33) of a reply (MAC; RAND) to said challenge (RAND); transmitting said reply (MAC; RAND) to the terminal (10); returning by the terminal (10) a message (GA-RC Register Request) containing said reply; verifying the reply (MAC; RAND) contained in said message. The invention is applicable to access to a mobile telephone system operator's network via a stationary telephone network.