EP4104478A1 - Method and system of verifying mobile phone information of users who are connected to the internet with a wired/wireless gateway other than the gsm mobile network with a mobile device in the gsm mobile network area - Google Patents
Method and system of verifying mobile phone information of users who are connected to the internet with a wired/wireless gateway other than the gsm mobile network with a mobile device in the gsm mobile network areaInfo
- Publication number
- EP4104478A1 EP4104478A1 EP21771313.0A EP21771313A EP4104478A1 EP 4104478 A1 EP4104478 A1 EP 4104478A1 EP 21771313 A EP21771313 A EP 21771313A EP 4104478 A1 EP4104478 A1 EP 4104478A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- user
- mobile device
- information
- gsm
- isp
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000000034 method Methods 0.000 title claims description 25
- 238000012795 verification Methods 0.000 claims abstract description 58
- 230000001960 triggered effect Effects 0.000 claims description 2
- VJYFKVYYMZPMAB-UHFFFAOYSA-N ethoprophos Chemical compound CCCSP(=O)(OCC)SCCC VJYFKVYYMZPMAB-UHFFFAOYSA-N 0.000 description 4
- 238000012790 confirmation Methods 0.000 description 1
- 230000001419 dependent effect Effects 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000010354 integration Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/126—Anti-theft arrangements, e.g. protection against subscriber identity module [SIM] cloning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
- H04L63/0846—Network architectures or network communication protocols for network security for authentication of entities using passwords using time-dependent-passwords, e.g. periodically changing passwords
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/40—Security arrangements using identity modules
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/69—Identity-dependent
- H04W12/72—Subscriber identity
Definitions
- the invention relates to a method that enables to verify the phone number (MSISDN information) of the user who connects to the Internet via a wired/wireless gateway (6) with a Mobile Device (1) with a SIM Card (5) inserted and actively connected to the GSM Mobile Network, via the Internet Service Provider (ISP) (2) to which this gateway is connected.
- MSISDN information phone number
- ISP Internet Service Provider
- GGSN Gateway GPRS Support Node
- GGSN Header Enrichment Method GGSN Header Enrichment Method
- Method 2 In case the user's phone number is requested to be verified over the Mobile Device GSM line, a one-time password (OTP) method is used. Since this method requires human intervention, it is very vulnerable to Phishing attacks and its use is limited due to its risk.
- Method 3 Another solution is to request users to share their device information via a mobile application that they will download to their devices. In this solution, users do not want to give the necessary powers of applications that will collect the necessary information to such applications. Apart from this, it is necessary to verify with another device (SIM card) that is known to belong to the user at the first entry, or the institution to verify should have this information previously and through a verified channel. For these reasons, the implementation of the solution is insufficient.
- SIM card another device
- the invention verifies something you have, which is one of the three basic factors used for identity verification of users connected to the Internet via their mobile devices.
- the verification of the user is provided by using the information of the requester to be verified and the MSISDN information connected to the SIM card inserted in the mobile device to which this request is received.
- Another purpose of the invention is to provide a structure that eliminates user-dependent trust, unlike the solutions used in existing techniques. Thus, Phishing attacks are prevented. In this method, it will not be sufficient for the attacker to obtain only the required information of the user to be authenticated, but also they need to capture the device he/she owns, so such attacks will be substantially prevented.
- Another purpose of the invention is to verify the phone number of the user in the use of paid services behind Wired/Wireless networks and to perform charging based on this verification.
- Figure 2 A general flow chart diagram representation describing the method and alternative process steps of the invention.
- ISP Internet Service Provider
- the user sends a login request to the verification server.
- the Internet service provider assigns IP/PORT to the user for login requests.
- the verification server receives IP/PORT information from the incoming request.
- the verification server determines the reference of the operation and stores it in the database with IP/PORT and other information.
- the verification server sends a request for a reference URL to be triggered to the operator.
- the operator transmits the trigger request to the GSM Operator SIM Management Platform. 130.
- the Operator SIM Management Platform sends an SMS to the user's device in trigger mode.
- the device sends a request directly to the URL in the SMS.
- the device opens the application with Deep Link in SMS. 145.
- the application makes a call to the Verification server with the incoming reference code.
- the verification server receives the device's IP/PORT and other information.
- the verification server verifies the phone number in the requested request.
- the device shows the PoP-UP SMS to the user.
- the user connects to the User Verification Platform (3) via the wired/wireless Gateway (6) and the Internet Service Provider (ISP) (2) to which this network is connected, by using the Mobile Device (1) with SIM Card (5) inserted and actively connected to the GSM Mobile Network and requests to login (100).
- the IP and PORT information of the network to which the Mobile Device (1) sending this request is connected is assigned permanently or temporarily by the internet service provider (2) (105).
- the assigned IP and PORT information are transmitted to the User Verification Platform (3) along with the request (110) and this IP/PORT information and tracking/reference information of the user Mobile Device (1) are recorded in the Database (3.1) (115).
- the information therein is not limited to IP/PORT but may include all information such as location, a universally unique identifier (UUID), User-Agent, which are limited or fully identifiers of the device. This information alone does not give information about the user's ownership of the user device.
- the created tracking/reference information is unique for each operation and has a certain lifetime (Time to live (TTL)). The tracking/reference information cannot be reused after the first use. If more than one request with the same tracking/reference information reaches the verification server, the login request from all users with the relevant tracking/reference information is rejected and, if any, active connections are terminated.
- the User Verification Platform (3) sends a URL verification request containing single-use tracking/reference information to the GSM Operator (3) to transmit to the user's phone number to confirm the phone number of the person (120).
- the GSM Operator (4) creates the HTTPS connection via the GSM Operator SIM Management Platform (4.1) to access the single- use URL for the user's SIM card (5) according to the existing Global Platform v.2.2 Amendment B standards with the trigger mode (Push Mode) (125).
- a binary (binary, configurative, invisible, and unreadable to the user) SMS is sent to the SIM card (5) inserted in the Mobile Device (1) by the GSM Operator SIM Management Platform (4.1) (OTA) containing the request for connecting the URL containing the User Verification Platform (5) single-use tracking/reference information (130).
- GSM Operator SIM Management Platform 4.1
- OTA GSM Operator SIM Management Platform
- the sent Trigger SMS can be interpreted in three different ways on the user's device.
- the content of the Trigger SMS includes the URL to which the Mobile Device (1) should be connected.
- the Mobile Device (1) receiving this message realizes the request to connect to the URL specified in the SMS over the Internet Service Provider (ISP) (2) or 3G, 4G, or similar GSM networks in case of a connection problem on this network (135).
- the specified URL is the User Verification Platform (5) URL and the Mobile Device (1) connects to the User Verification Platform (5) by using this URL.
- the data received in the content of the trigger SMS is shown to the user on the screen as a pop-up SMS (165).
- the user is asked whether she/he will continue the operation/approve the operation by showing information about the login request.
- the operation verification request is transmitted to the User Verification Platform (5), together with all the information that is limited or fully identifying the device and is not limited to tracking/reference information (170).
- the URL in the Trigger SMS's content allows the Mobile Device (1) to open this mobile application directly by using the Deep Link structure (140).
- the data in Deep Link is received by the Verification Platform Integrated Mobile Application running on the Mobile Device (1).
- the Verification Platform Integrated Mobile Application makes a direct call (145) to the User Verification Platform (5).
- the User Verification Platform (5) receives (150) the tracking/reference, IP/PORT information of the connected device, and all other information that is limited or fully identifying the Mobile Device (1).
- the device ownership of the user will be verified (160) by comparing with the IP address and PORT number (155) previously registered with the tracking/reference information and the information transmitted by the device by connecting with the URL after the trigger. Since the user did not/could not perform an active operation/correction/intervention during this verification operation, possible information sharing and user errors are prevented.
- the user's identity is verified by verifying the ownership of the SIM card number inserted in the Mobile Device.
- the device can also receive an SMS from networks, such as 2G/3G/4G, etc.
- networks such as 2G/3G/4G, etc.
- ISP Internet service provider
- it can switch to networks, such as 2G/3G/4G, etc. for data use.
- the user identity is verified by using the MSISDN Forwarding method.
- the verification operation is not limited to the registered user's mobile phone ownership in the login process, whether the user actually owns the claimed phone number in the new user registration process, the operation confirmation processes, but can be used in every operation that the user needs to authenticate.
- Wired/Wireless Gateway (6) to be used to connect the Mobile Device (1) to the Internet Service Provider (ISP) (2),
- ISP Internet service provider
- GSM Operator SIM Management Platform (4.1) that sends a trigger mode that includes a request to connect to a URL containing single-use tracking/reference information to the SIM card (5) inserted in the mobile device (1),
- the user connects to the User Verification Platform (3) via the wired/wireless Gateway (6) and the Internet Service Provider (ISP) (2) to which this network is connected, by using the Mobile Device (1) actively connected to the GSM Mobile Network and requests to login (100),
- ISP Internet Service Provider
- IP/PORT information is assigned (105) by the Internet Service Provider (ISP) (2) to the Mobile Device (1) or to the network to which it is connected specifically to the Mobile Device (1),
- ISP Internet Service Provider
- IP/PORT information assigned by the Internet Service Provider (ISP) (2) specifically to the Mobile Device (1) is received (110) from the incoming request by the User Verification Platform (3),
- the URL information containing the single-use tracking/reference information is forwarded (120) to the GSM Operator (4) to be sent to the user's phone number by the User Verification Platform (3),
- the GSM Operator (4) forwards (125) the incoming request to the GSM Operator SIM Management Platform (4.1), • The GSM Operator SIM Management Platform (4.1) creates an HTTPS connection to access the single-use URL for the user's SIM card (5) according to the existing Global Platform v.2.2 Amendment B standards with the trigger mode (Push Mode),
- a binary (binary, configurative, invisible, and unreadable to the user) SMS is sent to the SIM card (5) inserted in the Mobile Device (1) by the GSM Operator SIM Management Platform (4.1) (OTA) containing the request for connecting the URL containing the User Verification Platform (5) single-use tracking/reference information (130),
- OTA GSM Operator SIM Management Platform
- the sent Trigger SMS is interpreted in one of three different ways on the user's device, o Mobile Device (1) that receives the message of connecting to a single-use URL address, accesses (135) the URL address specified in the SMS via the Wired/Wireless Gateway (6) and the Internet Service Provider (ISP) (2), o The Mobile Device (1), which receives the message to connect to the single-use URL address, shows the user the login request information on the screen as a Pop- Up SMS (165) and according to the response from the user, makes a request (170) to the URL address specified in the SMS through Wired/Wireless Gateway (6) and the Internet Service Provider ( ISP) (2), o The Mobile Device (1), which receives the message to connect to the single-use URL address, opens the User Verification Platform Integrated Mobile Application installed thereon (140), shows the login request information to the user with the data in Deep Link and according to the response from the user or without showing any information to the user, makes requests (145) directly to the User Authentication Platform (3), via the Wired/
- the Mobile Device (1) connects to the User Verification Platform (3) by using the URL routing received by the Trigger Mode SMS, so receives (150) the IP/PORT information assigned by the Internet Service Provider (ISP) (2) to which the Mobile Device (1) is connected, and all other information that is limited or fully identifying the Mobile Device (1) and compares (155) IP/PORT information and all other information that is limited or fully identifying the Mobile Device (1) stored in the database using the tracking/reference information of the User Verification Platform (3) as a result of which the user's telephone number information is verified (160).
- ISP Internet Service Provider
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
TR2020/04363A TR202004363A2 (en) | 2020-03-20 | 2020-03-20 | The method and system of verifying the mobile phone information of the users who are connected to the Internet with a Mobile Device in the GSM Mobile Network area and a Wired/Wireless gateway outside the GSM Mobile Network |
PCT/TR2021/050228 WO2021188081A1 (en) | 2020-03-20 | 2021-03-15 | Method and system of verifying mobile phone information of users who are connected to the internet with a wired/wireless gateway other than the gsm mobile network with a mobile device in the gsm mobile network area |
Publications (2)
Publication Number | Publication Date |
---|---|
EP4104478A1 true EP4104478A1 (en) | 2022-12-21 |
EP4104478A4 EP4104478A4 (en) | 2023-07-26 |
Family
ID=77771139
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
EP21771313.0A Withdrawn EP4104478A4 (en) | 2020-03-20 | 2021-03-15 | Method and system of verifying mobile phone information of users who are connected to the internet with a wired/wireless gateway other than the gsm mobile network with a mobile device in the gsm mobile network area |
Country Status (3)
Country | Link |
---|---|
EP (1) | EP4104478A4 (en) |
TR (1) | TR202004363A2 (en) |
WO (1) | WO2021188081A1 (en) |
Families Citing this family (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN114390461A (en) * | 2022-01-17 | 2022-04-22 | 湖南塔澳通信有限公司 | SIM card pool resource management platform |
Family Cites Families (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP3975061B2 (en) * | 2001-03-29 | 2007-09-12 | ソフトバンクモバイル株式会社 | Authentication system |
JP4311617B2 (en) * | 2003-03-28 | 2009-08-12 | 三菱電機株式会社 | Terminal device |
JP2006268641A (en) * | 2005-03-25 | 2006-10-05 | Nec Corp | Authentication method and authentication system |
CN102437914B (en) * | 2010-12-08 | 2013-12-04 | 袁永亮 | Method by utilizing telecommunication network to supply user identity label and user identity authentication to Internet service |
WO2014032549A1 (en) * | 2012-08-31 | 2014-03-06 | 宝利数码有限公司 | Telecommunication service provider based mobile identity authentication and payment method and system |
JP2015231177A (en) * | 2014-06-06 | 2015-12-21 | 日本電信電話株式会社 | Device authentication method, device authentication system, and device authentication program |
CN108990059B (en) * | 2017-06-02 | 2021-06-29 | 创新先进技术有限公司 | Verification method and device |
US10277586B1 (en) * | 2018-10-29 | 2019-04-30 | Syniverse Technologies, Llc | Mobile authentication with URL-redirect |
-
2020
- 2020-03-20 TR TR2020/04363A patent/TR202004363A2/en unknown
-
2021
- 2021-03-15 WO PCT/TR2021/050228 patent/WO2021188081A1/en unknown
- 2021-03-15 EP EP21771313.0A patent/EP4104478A4/en not_active Withdrawn
Also Published As
Publication number | Publication date |
---|---|
TR202004363A2 (en) | 2021-09-21 |
EP4104478A4 (en) | 2023-07-26 |
WO2021188081A1 (en) | 2021-09-23 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US8533798B2 (en) | Method and system for controlling access to networks | |
KR101202671B1 (en) | Remote access system and method for enabling a user to remotely access a terminal equipment from a subscriber terminal | |
US10110416B2 (en) | Method and system for user equipment configuration | |
CA2789495C (en) | Seamless mobile subscriber identification | |
US20040152446A1 (en) | Method for providing network access to a mobile terminal and corresponding network | |
US7853705B2 (en) | On demand session provisioning of IP flows | |
US7526642B2 (en) | Controlling delivery of certificates in a mobile communication system | |
JP2008518533A (en) | Method and system for transparently authenticating mobile users and accessing web services | |
US11184356B1 (en) | System and method for seamless user equipment authentication | |
CN105722072A (en) | Business authorization method, device, system and router | |
US7558233B2 (en) | System and method for managing access of a communication network to a mobile terminal | |
EP4104478A1 (en) | Method and system of verifying mobile phone information of users who are connected to the internet with a wired/wireless gateway other than the gsm mobile network with a mobile device in the gsm mobile network area | |
US11968531B2 (en) | Token, particularly OTP, based authentication system and method | |
US20080052771A1 (en) | Method and System for Certifying a User Identity | |
US20060111087A1 (en) | Generation of service agreements for the use of network internal functions in telecommnication networks | |
EP1843541B1 (en) | A method of securing communication between an access network and a core network | |
US11284459B2 (en) | Data access security | |
KR20050077976A (en) | A method for providing session information for wireless data service and a system for enabling the method | |
KR20240042960A (en) | Enterprise dedicated network service system for providing multi authentication | |
CN118056448A (en) | Method, device and system for registering a terminal to a communication network |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
17P | Request for examination filed |
Effective date: 20220916 |
|
AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
REG | Reference to a national code |
Ref country code: DE Ref legal event code: R079 Free format text: PREVIOUS MAIN CLASS: H04W0012060000 Ipc: H04W0012126000 |
|
DAV | Request for validation of the european patent (deleted) | ||
DAX | Request for extension of the european patent (deleted) | ||
A4 | Supplementary search report drawn up and despatched |
Effective date: 20230622 |
|
RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04W 12/06 20210101ALI20230616BHEP Ipc: H04W 12/72 20210101ALI20230616BHEP Ipc: H04W 4/14 20090101ALI20230616BHEP Ipc: H04L 9/40 20220101ALI20230616BHEP Ipc: H04W 12/40 20210101ALI20230616BHEP Ipc: H04W 12/126 20210101AFI20230616BHEP |
|
STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
18D | Application deemed to be withdrawn |
Effective date: 20240123 |