Access Controller IMSI Verification via Core Network Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless mobile communication systems face security concerns due to unauthorized infiltration, particularly in IP communications, where verification of mobile user identities across different network interfaces is complex and resource-intensive, and may not always include necessary IMSI information.
Innovation Solution
The solution involves utilizing the Dual Transfer Mode (DTM) functionality to ensure that the International Mobile Subscriber Identity (IMSI) is consistently verified across circuit-switched and packet-switched domains by receiving and comparing IMSI information from both core network facilities within the radio access network controller, leveraging existing communication protocols to support resource allocation and identity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the access controller verifies mobile user identity by analyzing upper layer message traffic between MS and MSC, then identity verification is achieved, but processing complexity and resource consumption increase substantially
Solution Approach 1:
The patent extracts the IMSI verification function from the complex upper layer message analysis process. Instead of analyzing entire Layer 3 mobility management messages, the access controller extracts only the necessary IMSI information from incoming messages from the core network facility and compares it with the IMSI provided by the mobile station, significantly reducing processing complexity while maintaining verification reliability
Solution Approach 2:
The patent applies preliminary action by having the access controller receive and store the IMSI from the core network facility in advance, before the mobile station connection is established. This pre-retrieved IMSI is then readily available for immediate comparison with the mobile station's provided IMSI, eliminating the need for complex real-time message analysis
2Reliability
If the access controller analyzes upper layer message traffic to verify IMSI consistency, then security is improved, but processing power consumption increases
Solution Approach 1:
The patent extracts only the essential IMSI data element from the message traffic for verification purposes, rather than processing entire upper layer messages. This extraction approach maintains security by verifying IMSI consistency while dramatically reducing the computational power required, as the access controller only needs to compare two IMSI strings rather than analyze complex protocol messages
3Object-affected harmful factors
If the access controller uses TMSI instead of IMSI for communication, then user privacy is protected, but identity verification becomes more difficult
Solution Approach 1:
The patent applies preliminary action by having the access controller obtain and store the original IMSI from the core network facility before the mobile station connection is established. This pre-retrieved IMSI serves as a reference for verification, allowing the controller to verify the mobile station's identity even when the station uses TMSI for privacy-protection during normal communication
Solution Approach 2:
The patent uses the core network facility as an intermediary to provide the authentic IMSI to the access controller. This intermediary role allows the mobile station to maintain privacy by using TMSI in communications while the access controller still has access to the original IMSI through the core network for verification purposes
Data Source
AI summary
An identifier, required by a radio access network controller in order to support resource allocation associated with a predetermined condition, is sent from a core network to the radio access network controller independently of the predetermined condition. The identifier is thus available to the radio access network controller for verification of mobile user identity, regardless of whether it is needed to support resource allocation. A radio access network controller can receive an identifier in a communication sent by a core network according to a communication protocol. The radio access network controller terminates the communication protocol to access the communication, and uses the identifier for verification of mobile user identity.


