Verifying Legitimacy of IP-Connected Access Points

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of femto base stations (access points) in telecommunications networks poses challenges in ensuring security and determining location for accurate tariff application, as they are not under direct network provider control and can be mobile, necessitating verification of their legitimacy and location before communication.

Innovation Solution

A method to determine the validity of an IP-transport connected base station by receiving an initiation signal, identifying base station identifiers, and confirming if they match allowable entries in a profile, enhancing network security and location determination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access points are deployed in environments not directly under network provider control, then network capacity is increased and coverage is extended, but security cannot be guaranteed for each subscriber

Engineering Contradiction:
Improvenetwork capacityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network performs preliminary verification of the access point's legitimacy by checking identifiers (MAC address, IP address, DSL ID) against authorized lists before allowing any communication to proceed. This preventive measure ensures that only authenticated access points can establish connections, resolving the security concern while maintaining the ability to deploy APs in diverse environments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary verification mechanism between the mobile terminal and the access point. The network acts as a mediator that authenticates the access point's identifiers and establishes a trusted connection before allowing subscriber communications, thus guaranteeing security without restricting the deployment flexibility of access points.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access points are made mobile to increase flexibility, then ease of operation is improved, but location determination for accurate tariff application becomes difficult

Engineering Contradiction:
ImproveflexibilityVSAvoidlocation determination
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system continuously monitors the actual location of mobile access points and provides feedback to the tariff application system. Location information is collected from the access point's operational data and used to determine the correct tariff rate, enabling accurate location-based pricing even when access points are mobile.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The invention makes the location determination system dynamic by continuously updating the perceived location of mobile access points. The system adapts to the mobile nature of access points by using current operational location data rather than fixed registered locations, allowing accurate tariff application to follow the access point regardless of its physical position.

Inventive Principle:
Principle #15Dynamics

3Reliability

If access points are verified before communication to ensure security, then reliability is improved, but communication setup time increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidcommunication setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The access point verification process is performed in advance during the access point registration phase, before any subscriber communications begin. By completing the security check beforehand and storing the authorized identifiers, the system eliminates the need for repeated verification during communication setup, thus maintaining high security without adding setup time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access point performs self-identification by providing its own identifiers (MAC address, IP address, DSL ID) to the network for verification. This self-service approach streamlines the verification process and reduces the time required for authentication, as the access point initiates the verification rather than being passively checked.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2082554B1Controlling the use of access points in a telecommunications network
Publication Date: 2012.03.28 VODAFONE GRP PLC
  • EP2082554B1 patent drawingFigure 1
  • EP2082554B1 patent drawingFigure 2
  • EP2082554B1 patent drawingFigure 3

AI summary

A GSM or UMTS mobile telecommunications network is disclosed. In addition to the conventional radio access network comprising the base stations (3), one or more additional access points (20) are provided. An access point (20) is connected to the network core (12) by an IP transport broadband connection. The access point (20) is configured to appear to the mobile terminal 1 as a conventional base station - that is, it communicates with the mobile terminal using GSM or UMTS transport protocols and does not require any modification to a standard GSM or UMTS mobile terminal. Access Points are typically not under the direct control of the network provider, and so are more susceptible to security threats, such as illicit eavesdropping of user data. Arrangements are therefore disclosed which allow the network provider to verify that the access point a mobile terminal is about to commence communicating through is a legitimate and trusted base station and/or is at a particular location. By confirming the legitimacy of the base station to the mobile terminal before communication commences, and accordingly before sensitive information is transmitted to the network provider via the base station, enhanced network security can be achieved. Differential charging may be performed in dependence upon a subscriber's location.