Third-Party App Authentication via Alternate Secret Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Third-party applications on smartphones are unable to authenticate with networks using SIM-based methods due to restricted access to SIM-based secret keys, leading to the need for multiple authentication methods and increased complexity in network security architectures.

Innovation Solution

Implementing an alternate secret key within the standard network security architecture to enable third-party applications to perform authentication using EAP-AKA or EAP-SIM protocols, allowing them to establish IPsec SA and simplify access network security by using an evolved Packet Data Gateway (ePDG) or Security Gateway (SeGW).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM-based authentication methods are used, then security and reliability are improved, but device complexity increases due to restricted SIM access for third-party applications

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication credentials by creating a separate authentication key package (AKP) that is distinct from the SIM card. This allows third-party applications to have their own dedicated authentication credentials (application-specific authentication keys) rather than requiring access to the SIM card, thereby maintaining security while reducing complexity for non-native applications

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the network infrastructure mediates between the third-party application and the core network. The application communicates with the network using its own authentication credentials, and the network handles the authentication process without requiring direct SIM card access, thus acting as an intermediary that resolves the access restriction issue

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple authentication methods are deployed for third-party applications, then compatibility is improved, but device complexity and protocol diversity increase

Engineering Contradiction:
Improveapplication compatibilityVSAvoidauthentication protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework where the EAP-AKA protocol can serve both native applications (using SIM credentials) and third-party applications (using AKP credentials). The network infrastructure is designed to handle both types of credentials through the same protocol framework, making the system multi-functional without requiring separate protocol stacks for different application types

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If third-party applications are given access to SIM credentials, then ease of operation is improved, but security is worsened due to potential key exposure

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecret key exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication functionality from the SIM card and creates a separate authentication key package (AKP) that can be securely stored in the application's sandbox. This extraction allows third-party applications to have direct access to their own credentials without needing to access the SIM card, maintaining ease of operation while eliminating the security risk of SIM key exposure

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10902110B2Use of AKA methods and procedures for authentication of subscribers without access to SIM credentials
Publication Date: 2021.01.26 RIBBON COMMUNICATIONS OPERATING CO INC
  • US10902110B2 patent drawing
  • US10902110B2 patent drawing
  • US10902110B2 patent drawing

AI summary

Systems and methods which enable an authentication procedure to be used within the standard network security architecture to authenticate third party applications that are forbidden access to a particular secret key are disclosed. Third party smartphone applications that are unable to use SIM-based authentication due to being forbidden access to a SIM-based key are provided an alternate secret key for use in an EAP-AKA or EAP-SIM type procedure according to embodiments. An authentication server or other backend authentication infrastructure of embodiments requests authentication vectors from a backend system sharing the alternative secret key. Accordingly, the backend authentication platform of embodiments is adapted to know or detect that an application is using an alternative secret key (e.g., a secret key other than the SIM-based secret key) and to perform the appropriate procedure for the key type.