Transaction Identifier Validity Verification in 3G Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 3G wireless communication systems, the generic authentication architecture lacks a mechanism to verify the validity of transaction identifiers (TIDs), leading to potential security vulnerabilities and unmanaged TID usage, which can result in permanent validity and increased risk of key theft.

Innovation Solution

Implementing a method where Network Application Functions (NAFs) check the validity of TIDs by determining their expiration dates and, if expired, instruct users to perform bootstrapping authentication again, ensuring that TIDs are managed effectively and securely by assigning a term of validity, thereby enhancing system security and enabling easy billing integration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If TIDs are assigned without expiration validation, then ease of operation is improved, but security deteriorates due to permanent validity and key theft risk

Engineering Contradiction:
ImproveTID usage convenienceVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an expiration date parameter for TIDs, changing the state from permanent validity to time-limited validity. The BSF assigns an expiration date when creating TIDs, and NAFs validate this parameter during TID verification, thereby resolving the security issue while maintaining operational simplicity through automated validation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If TID validity checking is implemented, then security is improved, but device complexity increases due to additional validation steps

Engineering Contradiction:
Improvesystem securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service validation where the NAF automatically checks TID expiration dates against the BSF without requiring manual intervention. The system performs self-verification by querying the BSF for TID status and automatically enforcing validity checks, reducing operational complexity despite adding security validation steps.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If TIDs have permanent validity, then ease of operation is maintained, but loss of information increases due to unmanaged TID usage

Engineering Contradiction:
Improvecontinuous service availabilityVSAvoidTID management control
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements periodic validation of TID expiration dates. Instead of permanent validity, TIDs are validated at regular intervals against their assigned expiration dates. The NAF periodically checks whether the current time exceeds the TID expiration date, ensuring managed TID usage while maintaining continuous service availability through automated renewal or rejection processes.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS7941121B2Method for verifying the validity of a user
Publication Date: 2011.05.10 SNAPTRACK INC
  • US7941121B2 patent drawing
  • US7941121B2 patent drawing
  • US7941121B2 patent drawing

AI summary

The invention disclose a method for verifying the validity of a user, making full use of a TID as the bridge for establishing confidence between a NAF and a user equipment, and the BSF assigning a term of validity for the TID, thereby extending the function of the TID, enabling the NAF to verify the term of validity for using the TID, and accordingly, achieving a further verification of the validity to the user. By using the method of the invention, it is possible to avoid the situation in which one TID is permanently valid for one or more NAFs, enhance the system security, decrease the risks caused by the theft of users' TID and corresponding secret keys, and at the same time, implement TID management by the NAF. In addition, a combination of the method with billing system makes it easy to implement the function of charging a user.