Authentication Server Shared IMSI Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing method of pre-allocating unique IMSI/K pairs to communication devices is costly and inefficient, as it leads to unused IMSI numbering space and cumbersome scheduling for shared IMSI usage, especially when devices support non-3GPP network access technologies.

Innovation Solution

An authentication server and communication device system that allocates a unique subscription identity by deriving a key using a key derivation function applied to a random number and a shared key associated with a predetermined subscription identity, allowing multiple devices to share a common IMSI/K pair, with the authentication server managing the process to ensure secure and efficient connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a unique IMSI/K pair is pre-allocated to each communication device, then each device can independently attach to the network, but it leads to waste of IMSI numbering space and increases cost

Engineering Contradiction:
Improveindependent network attachment capabilityVSAvoidIMSI numbering space
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

Multiple communication devices share a common IMSI/K pair instead of each having a unique one. The network apparatus coordinates attachment requests so that only one device uses the common IMSI at a time, merging the identity resources of multiple devices into a single shared credential set.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

A single IMSI/K pair serves multiple communication devices simultaneously, making the subscription identity universal across different devices. The same credential can be used by any device in the group, eliminating the need for device-specific unique identifiers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of substance

If a common IMSI/K pair is shared among multiple communication devices, then IMSI numbering space is saved, but careful scheduling and management is required which is cumbersome and costly

Engineering Contradiction:
ImproveIMSI numbering spaceVSAvoidscheduling management complexity
Core Design Contradiction:
Loss of substanceVSDevice complexity

Solution Approach 1:

The system enables automatic coordination of attachment requests without requiring manual scheduling intervention. The network apparatus handles the coordination automatically, allowing devices to autonomously attempt attachment while the system manages conflicts through standardized procedures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically manages the common IMSI usage by coordinating attachment requests in real-time. When one device is attached, other devices are temporarily blocked from using the same IMSI, and this state changes dynamically as devices attach and detach from the network.

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If a common IMSI/K pair is pre-allocated to multiple communication devices, then device provisioning cost is reduced, but the network apparatus cannot handle multiple simultaneous attachment requests with the same IMSI

Engineering Contradiction:
Improvedevice provisioning costVSAvoidsimultaneous attachment handling capacity
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The network apparatus acts as an intermediary that coordinates between multiple devices seeking to use the common IMSI and the authentication server. It manages the timing and sequencing of authentication requests, ensuring that only one device attempts to attach with the common IMSI at a time while maintaining the ability to serve multiple devices overall.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9331993B2Authentication server and communication device
Publication Date: 2016.05.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9331993B2 patent drawing
  • US9331993B2 patent drawing
  • US9331993B2 patent drawing

AI summary

A communication device comprising a central processing unit (CPU) and a memory device is disclosed. The CPU is configured to send a first attach request including a first subscription identity (FSI) to the network apparatus, receive an authentication request including a random number and an authentication token from the network apparatus as a response to the first attach request. Further, the CPU is configured to authenticate the authentication token using the random number and a first key associated with the FSI, obtain a second key and a second subscription identity (SSI) in response to authentication of the authentication token failing, where SSI is obtained from the authentication request. The CPU is further configured to send an authentication failure to the network apparatus. The second key and SSI are stored in the memory device such that the second key is associated with SSI.