VPN Authentication via HSS Token Gateway

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing VPN authentication methods face security issues due to the potential misuse of knowledge factors, such as stolen passwords or PINs, and the difficulty in ensuring that a device is being used by the intended user, particularly in multi-factor authentication systems that rely on physical or virtual tokens.

Innovation Solution

The proposed solution involves generating a token code at a remote Home Subscriber Server (HSS) and using a token gateway to securely transmit this code to the user's device through a cellular network, combining it with user-provided information like a PIN or password for enhanced security, utilizing protocols like SMPP and TLS for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multi-factor authentication using software or hardware tokens is used, then user identity verification is improved, but the system remains vulnerable to stolen passwords and PINs

Engineering Contradiction:
Improveauthentication securityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where a token gateway and home subscriber server act as mediators between the user and the VPN server. The system generates one-time passwords through these intermediaries rather than relying directly on user-held tokens, adding a layer of security that prevents unauthorized access even if user credentials are compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/token-based authentication system (software or hardware tokens held by users) with an electronic one-time password generation system. Instead of relying on physical or virtual tokens that users must protect, the system electronically generates secure one-time passwords through the token gateway and HSS, eliminating the security vulnerabilities associated with traditional token systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual entry of token codes is required, then authentication security is improved, but user convenience and operation ease deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the system automatically generates and delivers one-time passwords to users through the token gateway and HSS infrastructure. Users receive their authentication credentials automatically without needing to manually enter complex token codes, making the process both secure and convenient.

Inventive Principle:
Principle #25Self-service

3Reliability

If physical hardware tokens are used, then possession factor authentication is improved, but replacement and portability become physical constraints

Engineering Contradiction:
Improvepossession factor verificationVSAvoidtoken replacement process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the physical hardware token system with an electronic one-time password generation system managed through the token gateway and home subscriber server. This eliminates the need for physical token replacement and portability concerns, as the authentication system is delivered electronically and can be accessed remotely without physical constraints.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10348721B2User authentication
Publication Date: 2019.07.09 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10348721B2 patent drawing
  • US10348721B2 patent drawing
  • US10348721B2 patent drawing

AI summary

In one implementation, instructions stored on a non-transitory computer-readable medium are executable by a processing resource to cause a computing device to fetch a token code from a home subscriber server (HSS) for a user and log in to a Virtual Private Network (VPN) server using the token code.