User Device Authentication via Secondary Identifier and Authenticator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for user devices with application servers require manual entry of credentials, lack implicit authentication for users from different operators, and are insecure against interception and impersonation.
Innovation Solution
A method involving a user device obtaining a secondary identifier for notifications, sending a signaling message with the secondary identifier via a security module, and receiving an authenticator from the application server, which is then verified for secure authentication without manual credential entry, allowing implicit authentication even across different operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual credential entry is used for authentication, then user identification can be achieved, but the authentication process becomes complex and user-unfriendly
Solution Approach 1:
The system enables self-service authentication where the user device automatically performs authentication operations without manual credential entry. The device uses its own identifier (MSISDN) and receives an authenticator automatically, eliminating the need for users to manually input usernames and passwords.
Solution Approach 2:
The notification server acts as an intermediary that facilitates authentication by sending the authenticator to the user device. This mediator enables the authentication process without requiring direct manual interaction from the user, simplifying the interface while maintaining security.
2Adaptability or versatility
If implicit authentication is implemented for users from different operators, then cross-operator authentication is enabled, but security against interception and impersonation is compromised
Solution Approach 1:
The system performs preliminary actions by having the notification server generate and send the authenticator to the user device before the actual authentication request is made. This preliminary distribution of the authenticator ensures that only the intended device can complete authentication, preventing impersonation attacks.
Solution Approach 2:
The authentication process includes feedback verification where the application server validates the authenticator received from the user device against the expected authenticator. This feedback mechanism ensures security by confirming that the authentication request comes from the legitimate device that received the authenticator.
3Ease of operation
If account creation and credential memorization are required, then access rights can be managed, but user burden and authentication complexity increase
Solution Approach 1:
The system eliminates the need for manual account creation and credential memorization by using the user device's own identifier (MSISDN) as the authentication basis. The device automatically receives and uses the authenticator, making the entire authentication process self-service oriented and eliminating setup time for credential management.
Solution Approach 2:
The MSISDN serves multiple functions: it identifies the user device in the network, enables authentication, and acts as a universal identifier across different operators. This multi-functionality eliminates the need for separate account creation and credential management systems.
Data Source
Figure 1~4
Figure 2
AI summary
The invention relates to a technique for authenticating a user device (10) with a server implementing an application, termed the application package server (30). The device obtains (E2) an identifier, termed the secondary identifier, allowing it to receive notifications relating to the application. Next, the device dispatches (E3), while being identified by an identifier, termed the main identifier, associated with the device by way of a security module, a signalling message (M3) comprising the secondary identifier. Subsequent to this dispatching, the device receives (E4) a notification (M6) relating to the application which is addressed to it while being identified by the secondary identifier. This notification, the dispatching of which has been commanded (G2) by the application package server, comprises the main identifier and an authenticator. The device then dispatches (E5) an authentication request (M7) to the application package server. This authentication request comprises the main identifier and the authenticator that were received. The device is authenticated (G3) by the application package server by means of this main identifier in association with this secondary identifier.