Verifying Legitimacy of IP-Connected Access Points
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of femto base stations (access points) in telecommunications networks poses challenges in ensuring security and determining location for accurate tariff application, as they are not under direct network provider control and can be mobile, necessitating verification of their legitimacy and location before communication.
Innovation Solution
A method to determine the validity of an IP-transport connected base station by receiving an initiation signal, identifying base station identifiers, and confirming if they match allowable entries in a profile, enhancing network security and location determination.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If access points are deployed in environments not directly under network provider control, then network capacity is increased and coverage is extended, but security cannot be guaranteed for each subscriber
Solution Approach 1:
The network performs preliminary verification of the access point's legitimacy by checking identifiers (MAC address, IP address, DSL ID) against authorized lists before allowing any communication to proceed. This preventive measure ensures that only authenticated access points can establish connections, resolving the security concern while maintaining the ability to deploy APs in diverse environments.
Solution Approach 2:
The invention introduces an intermediary verification mechanism between the mobile terminal and the access point. The network acts as a mediator that authenticates the access point's identifiers and establishes a trusted connection before allowing subscriber communications, thus guaranteeing security without restricting the deployment flexibility of access points.
2Ease of operation
If access points are made mobile to increase flexibility, then ease of operation is improved, but location determination for accurate tariff application becomes difficult
Solution Approach 1:
The system continuously monitors the actual location of mobile access points and provides feedback to the tariff application system. Location information is collected from the access point's operational data and used to determine the correct tariff rate, enabling accurate location-based pricing even when access points are mobile.
Solution Approach 2:
The invention makes the location determination system dynamic by continuously updating the perceived location of mobile access points. The system adapts to the mobile nature of access points by using current operational location data rather than fixed registered locations, allowing accurate tariff application to follow the access point regardless of its physical position.
3Reliability
If access points are verified before communication to ensure security, then reliability is improved, but communication setup time increases
Solution Approach 1:
The access point verification process is performed in advance during the access point registration phase, before any subscriber communications begin. By completing the security check beforehand and storing the authorized identifiers, the system eliminates the need for repeated verification during communication setup, thus maintaining high security without adding setup time.
Solution Approach 2:
The access point performs self-identification by providing its own identifiers (MAC address, IP address, DSL ID) to the network for verification. This self-service approach streamlines the verification process and reduces the time required for authentication, as the access point initiates the verification rather than being passively checked.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A GSM or UMTS mobile telecommunications network is disclosed. In addition to the conventional radio access network comprising the base stations (3), one or more additional access points (20) are provided. An access point (20) is connected to the network core (12) by an IP transport broadband connection. The access point (20) is configured to appear to the mobile terminal 1 as a conventional base station - that is, it communicates with the mobile terminal using GSM or UMTS transport protocols and does not require any modification to a standard GSM or UMTS mobile terminal. Access Points are typically not under the direct control of the network provider, and so are more susceptible to security threats, such as illicit eavesdropping of user data. Arrangements are therefore disclosed which allow the network provider to verify that the access point a mobile terminal is about to commence communicating through is a legitimate and trusted base station and/or is at a particular location. By confirming the legitimacy of the base station to the mobile terminal before communication commences, and accordingly before sensitive information is transmitted to the network provider via the base station, enhanced network security can be achieved. Differential charging may be performed in dependence upon a subscriber's location.