Access Controller IMSI Verification via Core Network Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless mobile communication systems face security concerns due to unauthorized infiltration, particularly in IP communications, where verification of mobile user identities across different network interfaces is complex and resource-intensive, and may not always include necessary IMSI information.

Innovation Solution

The solution involves utilizing the Dual Transfer Mode (DTM) functionality to ensure that the International Mobile Subscriber Identity (IMSI) is consistently verified across circuit-switched and packet-switched domains by receiving and comparing IMSI information from both core network facilities within the radio access network controller, leveraging existing communication protocols to support resource allocation and identity verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the access controller verifies mobile user identity by analyzing upper layer message traffic between MS and MSC, then identity verification is achieved, but processing complexity and resource consumption increase substantially

Engineering Contradiction:
Improveidentity verificationVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the IMSI verification function from the complex upper layer message analysis process. Instead of analyzing entire Layer 3 mobility management messages, the access controller extracts only the necessary IMSI information from incoming messages from the core network facility and compares it with the IMSI provided by the mobile station, significantly reducing processing complexity while maintaining verification reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary action by having the access controller receive and store the IMSI from the core network facility in advance, before the mobile station connection is established. This pre-retrieved IMSI is then readily available for immediate comparison with the mobile station's provided IMSI, eliminating the need for complex real-time message analysis

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the access controller analyzes upper layer message traffic to verify IMSI consistency, then security is improved, but processing power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential IMSI data element from the message traffic for verification purposes, rather than processing entire upper layer messages. This extraction approach maintains security by verifying IMSI consistency while dramatically reducing the computational power required, as the access controller only needs to compare two IMSI strings rather than analyze complex protocol messages

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If the access controller uses TMSI instead of IMSI for communication, then user privacy is protected, but identity verification becomes more difficult

Engineering Contradiction:
Improveuser privacy protectionVSAvoididentity verification difficulty
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by having the access controller obtain and store the original IMSI from the core network facility before the mobile station connection is established. This pre-retrieved IMSI serves as a reference for verification, allowing the controller to verify the mobile station's identity even when the station uses TMSI for privacy-protection during normal communication

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the core network facility as an intermediary to provide the authentic IMSI to the access controller. This intermediary role allows the mobile station to maintain privacy by using TMSI in communications while the access controller still has access to the original IMSI through the core network for verification purposes

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9113331B2Validating user identity by cooperation between core network and access controller
Publication Date: 2015.08.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9113331B2 patent drawing
  • US9113331B2 patent drawing
  • US9113331B2 patent drawing

AI summary

An identifier, required by a radio access network controller in order to support resource allocation associated with a predetermined condition, is sent from a core network to the radio access network controller independently of the predetermined condition. The identifier is thus available to the radio access network controller for verification of mobile user identity, regardless of whether it is needed to support resource allocation. A radio access network controller can receive an identifier in a communication sent by a core network according to a communication protocol. The radio access network controller terminates the communication protocol to access the communication, and uses the identifier for verification of mobile user identity.