Asymmetric Authentication for Decentralized Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing centralized symmetric authentication systems in mobile networks are not scalable for the anticipated expansion to millions of decentralized mobile networks, and they pose security risks due to the caching of symmetric keys across nodes.

Innovation Solution

Implementing asymmetric authentication using a decentralized authentication approach via an extensible authentication protocol (EAP)-dAKA mechanism, which utilizes public-private keypairs and a blockchain-based distributed ledger to manage the lifecycle of decentralized electronic subscriber identity modules (dSIMs).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized symmetric authentication is used, then existing mobile networks can operate, but scalability is limited and security risks arise from key caching

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies asymmetric authentication instead of symmetric authentication. Each device generates a public-private key pair where the private key remains local and the public key is shared with the network. This asymmetric approach eliminates the need for centralized key distribution and caching, thereby improving both security (private keys never leave the device) and scalability (no key management bottleneck).

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent extracts the authentication credential (private key) from the centralized network control and keeps it locally within each device's secure element. This extraction eliminates the security vulnerability of key caching in the network while maintaining authentication functionality through public key verification.

Inventive Principle:
Principle #2Taking out (Extraction)

2Speed

If symmetric keys are cached across network nodes, then authentication speed is maintained, but security vulnerabilities increase

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces public keys as an intermediary that enables authentication without exposing private keys. The public key acts as a safe mediator that can be cached and shared across network nodes for verification, while the actual private key remains secure locally, thus maintaining authentication speed without the security risks of caching sensitive credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If decentralized networks expand to millions of operators, then network coverage and options increase, but existing authentication systems become impractical

Engineering Contradiction:
Improvenetwork expansion capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where each device independently generates its own cryptographic key pair and manages its own credentials. This eliminates the need for complex centralized authentication infrastructure to scale with millions of operators, as each device autonomously performs authentication functions that would otherwise require complex network-wide key management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12273472B2Systems and methods for asymmetric authentication in decentralized mobile networks
Publication Date: 2025.04.08 BLOXTEL INC
  • US12273472B2 patent drawing
  • US12273472B2 patent drawing
  • US12273472B2 patent drawing

AI summary

An apparatus includes a processing device, communications hardware configured to enable wireless communication by the apparatus, and a universal integrated circuit card (UICC). The UICC stores a decentralized electronic subscriber identity module (dSIM) that hosts a decentralized access application that is configured to exchange information with a decentralized mobile network core utilizing the communications hardware to perform an asymmetric authentication session.