Access Network Interception for User Association Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current services and applications lack reliable authentication methods for 'household' or 'business location' associations, making it difficult for service providers to verify user groups sharing a common subscription.

Innovation Solution

A method and module that intercept and modify signalling messages in access networks to include and authenticate identification information, using techniques like X.509 certificates, reputation networks, or identity assertions, ensuring that the service provider can verify the association between users and their subscription status.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If service providers allow multiple users to share a common subscription without reliable authentication, then subscription flexibility and ease of operation are improved, but system reliability and security deteriorate due to inability to verify legitimate household or business location associations

Engineering Contradiction:
Improvesubscription management flexibilityVSAvoiduser association authentication
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an access network as an intermediary between users and service providers. The access network intercepts signalling messages, extracts household identification information, and provides this information to the service provider for verification. This mediator approach enables reliable authentication of user associations without requiring direct complex authentication mechanisms between users and service providers, thus maintaining ease of operation while improving reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication by intercepting and analyzing signalling messages before service delivery. The access network extracts household identification information from signalling messages in advance, allowing the service provider to verify user associations before granting access to shared subscriptions. This preliminary action prevents unauthorized access while maintaining subscription flexibility

Inventive Principle:
Principle #10Preliminary action

2Reliability

If service providers implement reliable household authentication mechanisms, then system reliability and security are improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvehousehold authenticationVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By using the access network as an intermediary that already has visibility into signalling messages, the patent avoids the need for complex authentication infrastructure at the service provider end. The access network performs the complex task of extracting and verifying household identification information, while the service provider only needs to receive and process the provided identification, significantly reducing service provider system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access network performs authentication functions using its existing infrastructure and signalling message interception capabilities. By leveraging resources already present in the access network, the system avoids the need for additional complex authentication devices or infrastructure, reducing overall system complexity while maintaining reliable household authentication

Inventive Principle:
Principle #25Self-service

3Reliability

If service providers verify user associations through direct authentication protocols, then authentication reliability is improved, but signalling message overhead and processing time increase

Engineering Contradiction:
Improveuser verification accuracyVSAvoidsignalling processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The access network extracts household identification information from signalling messages in advance, during normal signalling operations. This preliminary extraction means that when the service provider receives the identification information, verification can proceed quickly without requiring time-consuming direct authentication protocols between users and service providers, reducing signalling processing time while maintaining verification accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts household identification information from existing signalling messages that are already being exchanged between users and service providers. By taking out this identification information from the signalling flow and providing it separately to the service provider, the system avoids the need for additional authentication signalling exchanges, reducing overall signalling overhead and processing time while maintaining reliable user verification

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2249540B1Method for verifying a user association, intercepting module and network node element
Publication Date: 2020.03.18 ALCATEL LUCENT SA
  • EP2249540B1 patent drawingFigure 1
  • EP2249540B1 patent drawingFigure 2A
  • EP2249540B1 patent drawingFigure 2B

AI summary

Method for verifying an association between a user and a group of users sharing a common subscription, comprising intercepting a message between a user and a service provider; adapting the message with information to include a guarantee to the service provider that the message is sent from a location allowed by the common subscription.