User Device Authentication via Secondary Identifier and Authenticator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for user devices with application servers require manual entry of credentials, lack implicit authentication for users from different operators, and are insecure against interception and impersonation.

Innovation Solution

A method involving a user device obtaining a secondary identifier for notifications, sending a signaling message with the secondary identifier via a security module, and receiving an authenticator from the application server, which is then verified for secure authentication without manual credential entry, allowing implicit authentication even across different operators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual credential entry is used for authentication, then user identification can be achieved, but the authentication process becomes complex and user-unfriendly

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system enables self-service authentication where the user device automatically performs authentication operations without manual credential entry. The device uses its own identifier (MSISDN) and receives an authenticator automatically, eliminating the need for users to manually input usernames and passwords.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The notification server acts as an intermediary that facilitates authentication by sending the authenticator to the user device. This mediator enables the authentication process without requiring direct manual interaction from the user, simplifying the interface while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If implicit authentication is implemented for users from different operators, then cross-operator authentication is enabled, but security against interception and impersonation is compromised

Engineering Contradiction:
Improvecross-operator authenticationVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by having the notification server generate and send the authenticator to the user device before the actual authentication request is made. This preliminary distribution of the authenticator ensures that only the intended device can complete authentication, preventing impersonation attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process includes feedback verification where the application server validates the authenticator received from the user device against the expected authenticator. This feedback mechanism ensures security by confirming that the authentication request comes from the legitimate device that received the authenticator.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If account creation and credential memorization are required, then access rights can be managed, but user burden and authentication complexity increase

Engineering Contradiction:
Improveuser authenticationVSAvoidaccount setup time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system eliminates the need for manual account creation and credential memorization by using the user device's own identifier (MSISDN) as the authentication basis. The device automatically receives and uses the authenticator, making the entire authentication process self-service oriented and eliminating setup time for credential management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The MSISDN serves multiple functions: it identifies the user device in the network, enables authentication, and acts as a universal identifier across different operators. This multi-functionality eliminates the need for separate account creation and credential management systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3456025B1Technique for authenticating a user device
Publication Date: 2021.11.17 ORANGE SA
  • EP3456025B1 patent drawingFigure 1~4
  • EP3456025B1 patent drawingFigure 2

AI summary

The invention relates to a technique for authenticating a user device (10) with a server implementing an application, termed the application package server (30). The device obtains (E2) an identifier, termed the secondary identifier, allowing it to receive notifications relating to the application. Next, the device dispatches (E3), while being identified by an identifier, termed the main identifier, associated with the device by way of a security module, a signalling message (M3) comprising the secondary identifier. Subsequent to this dispatching, the device receives (E4) a notification (M6) relating to the application which is addressed to it while being identified by the secondary identifier. This notification, the dispatching of which has been commanded (G2) by the application package server, comprises the main identifier and an authenticator. The device then dispatches (E5) an authentication request (M7) to the application package server. This authentication request comprises the main identifier and the authenticator that were received. The device is authenticated (G3) by the application package server by means of this main identifier in association with this secondary identifier.