Global Time-Based Authentication for Wireless Client Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for client devices on secured networks lack robustness, particularly for small cells that are vulnerable to tampering and unauthorized access due to their form factor and deployment in less secure locations.

Innovation Solution

Implementing a global time-based and location-based authentication system where client devices and security gateways use synchronized global time and location data to generate and compare responses to authentication challenges, allowing for multiple possible responses and expected responses to account for synchronization discrepancies and location changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for client devices, then the authentication process is simple, but the security against tampering and unauthorized access is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring client devices with unique identifiers and cryptographic keys before deployment. The security gateway pre-generates authentication challenges and stores expected responses, enabling proactive security validation rather than reactive response to breaches.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security gateway acts as an intermediary between client devices and the network, mediating all authentication transactions. It generates challenges, validates responses against expected values, and controls access based on cryptographic verification, providing a security buffer without requiring complex hardware in client devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If global time and location data are used for authentication, then security is enhanced, but the system requires more complex data synchronization

Engineering Contradiction:
Improveauthentication securityVSAvoidtime synchronization requirements
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses partial time and location data rather than requiring complete synchronization. Multiple possible expected responses are generated to account for time drift and location changes, allowing authentication to succeed even with partial data mismatch, thus reducing the impact of synchronization issues.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes parameters by incorporating dynamic time and location variables into the authentication process. By generating multiple expected responses that account for parameter variations, the system maintains security while accommodating natural drift in time synchronization and location data.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multiple possible responses are generated for authentication, then tolerance for synchronization discrepancies is improved, but the authentication process becomes more complex

Engineering Contradiction:
Improvetolerance for synchronization discrepanciesVSAvoidauthentication process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into distinct components: challenge generation, response generation, expected response creation, and validation. By dividing the process into manageable segments, the system can handle multiple possible responses systematically without overwhelming complexity, with each segment performing a specific function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security gateway performs multiple functions: it acts as a time server, location validator, challenge generator, response validator, and access controller. This multi-functionality consolidates complexity into a single device rather than distributing it across client devices, simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of manufacture

If expensive dedicated hardware is avoided, then cost-effectiveness is improved, but security robustness may be compromised

Engineering Contradiction:
Improvecost-effectivenessVSAvoidsecurity robustness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system replaces mechanical hardware-based security (such as dedicated security modules or hardware tokens) with software-based cryptographic authentication. By using software algorithms to generate and validate cryptographic responses, the system achieves robust security without requiring expensive dedicated hardware in client devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system uses cryptographic copies of security credentials (digital identifiers and keys) instead of physical security tokens. These digital copies can be securely stored in software and used for authentication without requiring physical hardware, reducing costs while maintaining security through cryptographic verification.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10171450B1Global time based authentication of client devices
Publication Date: 2019.01.01 T MOBILE INNOVATIONS LLC
  • US10171450B1 patent drawing
  • US10171450B1 patent drawing
  • US10171450B1 patent drawing

AI summary

A system for authenticating client devices for communication with one or more wireless communications networks, includes a client device configured to receive a client-side global time from a time tracking system and generate a response to an authentication challenge based on the authentication challenge, the client-side global time, a client device identifier associated with the client device, and optionally location data that corresponds to a location of the client device. The system further includes a security gateway configured to receive a gateway-side global time from the time tracking system, generate an expected response to the authentication challenge based on the authentication challenge, the gateway-side global time, the client device identifier, and optionally location data that corresponds to an expected location of the client device, receive the response to the authentication challenge, and authenticate the client device on a wireless communications network based on the response and the expected response.