Third-Party App Authentication via Alternate Secret Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Third-party applications on smartphones are unable to authenticate with networks using SIM-based methods due to restricted access to SIM-based secret keys, leading to the need for multiple authentication methods and increased complexity in network security architectures.
Innovation Solution
Implementing an alternate secret key within the standard network security architecture to enable third-party applications to perform authentication using EAP-AKA or EAP-SIM protocols, allowing them to establish IPsec SA and simplify access network security by using an evolved Packet Data Gateway (ePDG) or Security Gateway (SeGW).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM-based authentication methods are used, then security and reliability are improved, but device complexity increases due to restricted SIM access for third-party applications
Solution Approach 1:
The patent segments the authentication credentials by creating a separate authentication key package (AKP) that is distinct from the SIM card. This allows third-party applications to have their own dedicated authentication credentials (application-specific authentication keys) rather than requiring access to the SIM card, thereby maintaining security while reducing complexity for non-native applications
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the network infrastructure mediates between the third-party application and the core network. The application communicates with the network using its own authentication credentials, and the network handles the authentication process without requiring direct SIM card access, thus acting as an intermediary that resolves the access restriction issue
2Adaptability or versatility
If multiple authentication methods are deployed for third-party applications, then compatibility is improved, but device complexity and protocol diversity increase
Solution Approach 1:
The patent creates a universal authentication framework where the EAP-AKA protocol can serve both native applications (using SIM credentials) and third-party applications (using AKP credentials). The network infrastructure is designed to handle both types of credentials through the same protocol framework, making the system multi-functional without requiring separate protocol stacks for different application types
3Ease of operation
If third-party applications are given access to SIM credentials, then ease of operation is improved, but security is worsened due to potential key exposure
Solution Approach 1:
The patent extracts the authentication functionality from the SIM card and creates a separate authentication key package (AKP) that can be securely stored in the application's sandbox. This extraction allows third-party applications to have direct access to their own credentials without needing to access the SIM card, maintaining ease of operation while eliminating the security risk of SIM key exposure
Data Source
AI summary
Systems and methods which enable an authentication procedure to be used within the standard network security architecture to authenticate third party applications that are forbidden access to a particular secret key are disclosed. Third party smartphone applications that are unable to use SIM-based authentication due to being forbidden access to a SIM-based key are provided an alternate secret key for use in an EAP-AKA or EAP-SIM type procedure according to embodiments. An authentication server or other backend authentication infrastructure of embodiments requests authentication vectors from a backend system sharing the alternative secret key. Accordingly, the backend authentication platform of embodiments is adapted to know or detect that an application is using an alternative secret key (e.g., a secret key other than the SIM-based secret key) and to perform the appropriate procedure for the key type.


