Multi-Factor Authentication in 3GPP Networks Using UICC and Biometrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods in 3GPP cellular networks lack a comprehensive and secure multi-factor authentication process, particularly for user devices accessing sensitive information, which may compromise security and authorization.
Innovation Solution
The implementation of a multi-factor authentication process that combines user name and password verification with biometric information, utilizing a trusted execution environment and a universal integrated circuit card (UICC) within user devices, along with a bootstrapping architecture to create and manage secret keys for secure authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional single-factor authentication is used in 3GPP cellular networks, then the authentication process is simple and fast, but security is compromised when accessing sensitive information
Solution Approach 1:
The patent combines multiple authentication factors (something you know: PIN/password; something you have: UICC card; something you are: biometric data) into a unified multi-factor authentication process. This merging of different authentication modalities within the GBA framework achieves enhanced security while maintaining a structured authentication flow that manages complexity through standardized procedures.
2Reliability
If multi-factor authentication is implemented, then security is enhanced, but the authentication process becomes more complex and time-consuming
Solution Approach 1:
The patent performs preliminary authentication actions by establishing GBA bootstrapping credentials and secret keys before actual service access is required. The UICC stores pre-computed authentication vectors and the network pre-configures authentication parameters, allowing rapid multi-factor verification when needed without performing all computational steps in real-time.
3Reliability
If comprehensive authentication verification is performed, then authorization security is improved, but system complexity increases
Solution Approach 1:
The patent introduces the UICC (Universal Integrated Circuit Card) as an intermediary security element that stores and manages authentication credentials, secret keys, and authentication vectors. This intermediary component offloads complex cryptographic operations from the terminal device and network elements, centralizing security management while simplifying the overall system architecture through a dedicated security module.
Data Source
AI summary
A first network device is configured to receive a request for content from a user device, determine that the user device is not authenticated, and send information to the user device that the user device requires authentication. The first network device is configured further to receive authentication information for the user device from a second network device. The first network device is configured further to generate a secret key, authenticate the user device. The first network device is configured further to request user knowledge information from the user device, validate the user knowledge information and send the content to the user device.


