3GPP Network Authentication via Decentralized Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 3GPP-based networks authenticate SIM cards rather than the actual user, leading to unauthorized access and lack of user verification, as the user cannot be identified or authorized.

Innovation Solution

Implementing user ID as a decentralized identifier (DID) and DID-bound-VCs, which are stored on user equipment (UE), allowing user authentication and authorization by transmitting these credentials to the 3GPP network for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM card-based authentication is used, then network access is enabled, but actual user identification and authorization cannot be performed

Engineering Contradiction:
Improveuser authentication reliabilityVSAvoiduser identity information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the authentication process into two distinct parts: device authentication (via SIM card) and user authentication (via DID/VC). This allows the SIM card to continue providing network access while a separate user identification mechanism handles actual user verification, resolving the contradiction between maintaining network access and enabling user identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces DID (Decentralized Identifier) and VC (Verifiable Credential) as intermediary elements that bridge the gap between device authentication and user identification. These intermediaries carry user identity information without replacing the existing SIM card authentication mechanism, enabling both network access and user verification simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user identification mechanisms are added, then user authorization can be verified, but signaling overhead and complexity increase

Engineering Contradiction:
Improveuser authorization verificationVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the existing 3GPP authentication infrastructure multi-functional by enabling it to handle both device authentication and user authentication through the integration of DID/VC. The same signaling paths and network elements (AMF, UDM, AUFS) are reused for dual purposes, avoiding the need for separate dedicated user identification infrastructure and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The user's UE (User Equipment) autonomously manages its own user identification credentials (DID and VC) locally. The UE retrieves and presents these credentials during authentication without requiring external user identification servers or additional network infrastructure, enabling self-service user identification that reduces system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4614880A1User authentication in network environments
Publication Date: 2025.09.10 DEUTSCHE TELEKOM AG
  • EP4614880A1 patent drawingFigure 1~2
  • EP4614880A1 patent drawingFigure 3
  • EP4614880A1 patent drawingFigure 4~5

AI summary

A method and system for authentication and/or authorization of users in network environments, wherein the method comprises the following steps: • Provisioning of a user ID as a DID and a DID-bound-VC to a UE; • Provisioning network registration data to a 3GPP network access module; • Sending a network access registration message by means of the network access module, wherein the network access registration message comprises the network registration data of a 3GPP network provider and registering the network access module in the network of the network operator; • Transmitting the DID and the DID-bound-VC from the UE to the network access module; • Sending a user authentication message comprising the DID and the DID-bound-VC to the 3GPP network operator by means of the network access module; Provisioning of the DID and the DID-bound-VC to a verification unit, whereby the user is granted access to a service after successful authentication and/or authorization.