Application-Specific Credentials for Wireless Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for sponsored connectivity in wireless cellular systems face challenges such as user devices lacking operator credentials, scalability issues, unauthorized traffic, and lack of 'first-mile' defense, particularly for non-subscribed user devices attempting to access application service providers.
Innovation Solution
The implementation of application-specific credentials, including shared keys and public key certificates, allows user devices to securely access wireless networks for sponsored connectivity by provisioning credentials in a secure manner and performing authentication and key agreement within the wireless communication network, independent of the application service provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IP address based filtering is used for sponsored connectivity, then traffic can be filtered and sponsored access can be provided, but unauthorized traffic cannot be prevented, service gateways become vulnerable to overload attacks, and sponsors may be charged for non-service related traffic
Solution Approach 1:
The patent implements authentication and credential verification before allowing traffic to enter the core network. User devices must present valid credentials (such as SIM cards or registered device identifiers) and undergo authentication procedures prior to establishing sponsored connectivity. This preliminary security check prevents unauthorized devices from accessing the network and filtering traffic before it reaches service gateways, thereby preventing overload attacks and ensuring sponsors are only charged for legitimate service-related traffic.
2Adaptability or versatility
If user devices without SIM cards or cellular subscriptions attempt to access the wireless network, then sponsored connectivity can be provided to extend service coverage, but existing authentication mechanisms cannot verify such devices
Solution Approach 1:
The patent creates a universal authentication framework that works for both traditional SIM-card-based devices and non-SIM devices. The system accepts multiple types of credentials including SIM cards, device identifiers, and sponsor-provided credentials. The authentication mechanism is designed to be agnostic to the specific device type, allowing sponsors to register various devices (smartphones, tablets, IoT devices) without requiring them to have cellular subscriptions. This multi-functional approach enables broad sponsor coverage while maintaining a unified authentication process.
3Adaptability or versatility
If application service providers are charged for sponsored connectivity, then non-subscribed user devices can access services, but there is no mechanism to ensure accurate charging for only service-related traffic
Solution Approach 1:
The patent implements a feedback mechanism where the network continuously monitors and tracks traffic flows associated with sponsored connectivity. Authentication credentials are bound to specific user devices and services, allowing the system to track which devices access which services. The network generates detailed records of authenticated traffic, enabling accurate billing based on actual service usage. This feedback loop ensures sponsors are charged only for legitimate service-related traffic while preventing unauthorized or non-service traffic from being billed.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
At least one feature pertains to a method operational at a user device that includes receiving, from an application service provider, an application-specific certificate associated with at least one application service provided by the application service provider. The method also includes determining that a wireless communication network provides application-specific access to the application service provided by the application service provider, and transmitting a registration request including the application-specific certificate to the wireless communication network for authentication of the user device. The application-specific certificate includes a user device public key. The method further includes performing authentication and key agreement with the wireless communication network, and communicating with the application service after authentication and key agreement is successfully performed. In one aspect, authentication and key agreement with the network is performed directly between the user device and the network and independent to the application service provider.