Asymmetric Authentication for Decentralized Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing centralized symmetric authentication systems in mobile networks are not scalable for the anticipated expansion to millions of decentralized mobile networks, and they pose security risks due to the caching of symmetric keys across nodes.
Innovation Solution
Implementing asymmetric authentication using a decentralized authentication approach via an extensible authentication protocol (EAP)-dAKA mechanism, which utilizes public-private keypairs and a blockchain-based distributed ledger to manage the lifecycle of decentralized electronic subscriber identity modules (dSIMs).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized symmetric authentication is used, then existing mobile networks can operate, but scalability is limited and security risks arise from key caching
Solution Approach 1:
The patent applies asymmetric authentication instead of symmetric authentication. Each device generates a public-private key pair where the private key remains local and the public key is shared with the network. This asymmetric approach eliminates the need for centralized key distribution and caching, thereby improving both security (private keys never leave the device) and scalability (no key management bottleneck).
Solution Approach 2:
The patent extracts the authentication credential (private key) from the centralized network control and keeps it locally within each device's secure element. This extraction eliminates the security vulnerability of key caching in the network while maintaining authentication functionality through public key verification.
2Speed
If symmetric keys are cached across network nodes, then authentication speed is maintained, but security vulnerabilities increase
Solution Approach 1:
The patent introduces public keys as an intermediary that enables authentication without exposing private keys. The public key acts as a safe mediator that can be cached and shared across network nodes for verification, while the actual private key remains secure locally, thus maintaining authentication speed without the security risks of caching sensitive credentials.
3Adaptability or versatility
If decentralized networks expand to millions of operators, then network coverage and options increase, but existing authentication systems become impractical
Solution Approach 1:
The patent implements self-service authentication where each device independently generates its own cryptographic key pair and manages its own credentials. This eliminates the need for complex centralized authentication infrastructure to scale with millions of operators, as each device autonomously performs authentication functions that would otherwise require complex network-wide key management.
Data Source
AI summary
An apparatus includes a processing device, communications hardware configured to enable wireless communication by the apparatus, and a universal integrated circuit card (UICC). The UICC stores a decentralized electronic subscriber identity module (dSIM) that hosts a decentralized access application that is configured to exchange information with a decentralized mobile network core utilizing the communications hardware to perform an asymmetric authentication session.


