Multi-Factor Authentication in 3GPP Networks Using UICC and Biometrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in 3GPP cellular networks lack a comprehensive and secure multi-factor authentication process, particularly for user devices accessing sensitive information, which may compromise security and authorization.

Innovation Solution

The implementation of a multi-factor authentication process that combines user name and password verification with biometric information, utilizing a trusted execution environment and a universal integrated circuit card (UICC) within user devices, along with a bootstrapping architecture to create and manage secret keys for secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional single-factor authentication is used in 3GPP cellular networks, then the authentication process is simple and fast, but security is compromised when accessing sensitive information

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication factors (something you know: PIN/password; something you have: UICC card; something you are: biometric data) into a unified multi-factor authentication process. This merging of different authentication modalities within the GBA framework achieves enhanced security while maintaining a structured authentication flow that manages complexity through standardized procedures.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multi-factor authentication is implemented, then security is enhanced, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary authentication actions by establishing GBA bootstrapping credentials and secret keys before actual service access is required. The UICC stores pre-computed authentication vectors and the network pre-configures authentication parameters, allowing rapid multi-factor verification when needed without performing all computational steps in real-time.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive authentication verification is performed, then authorization security is improved, but system complexity increases

Engineering Contradiction:
Improveauthorization securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces the UICC (Universal Integrated Circuit Card) as an intermediary security element that stores and manages authentication credentials, secret keys, and authentication vectors. This intermediary component offloads complex cryptographic operations from the terminal device and network elements, centralizing security management while simplifying the overall system architecture through a dedicated security module.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8931068B2Authentication process
Publication Date: 2015.01.06 VERIZON PATENT & LICENSING INC
  • US8931068B2 patent drawing
  • US8931068B2 patent drawing
  • US8931068B2 patent drawing

AI summary

A first network device is configured to receive a request for content from a user device, determine that the user device is not authenticated, and send information to the user device that the user device requires authentication. The first network device is configured further to receive authentication information for the user device from a second network device. The first network device is configured further to generate a secret key, authenticate the user device. The first network device is configured further to request user knowledge information from the user device, validate the user knowledge information and send the content to the user device.