Authentication Server Secondary Identifier for UMB Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In ultra mobile broadband (UMB) networks, the secure distribution of a mobile device's network access identifier (NAI) and user profile information is challenging due to the decentralized architecture, which makes it difficult to authenticate access terminals and manage quality of service while maintaining security, especially when the NAI is anonymous and not transmitted over the air.

Innovation Solution

An authentication server generates a secondary user identifier associated with the primary user identifier for an access terminal, allowing secure authentication and distribution of user profile information without exposing the primary user identifier, and manages PMIP keys to ensure secure communication tunnel establishment and rerouting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the NAI is transmitted over the air to the PDSN for authentication and policy retrieval, then the authentication and QoS management can be performed, but the NAI becomes susceptible to snooping and insecure

Engineering Contradiction:
Improveauthentication securityVSAvoidsnooping vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the access terminal and the PDSN. The authentication server receives the NAI from the access terminal, performs authentication, and then provides a secondary identifier to the PDSN. This intermediary approach allows authentication to occur without exposing the NAI to the PDSN or transmitting it over the air, thereby resolving the contradiction between enabling authentication and preventing snooping vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the NAI is not sent over the air and anonymous NAI is implemented, then the security against snooping is improved, but the authentication and user profile retrieval become problematic

Engineering Contradiction:
Improvesnooping vulnerabilityVSAvoidauthentication process
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent segments the identifier system into two parts: a primary identifier (NAI) kept secure and unknown to the PDSN, and a secondary identifier transmitted to the PDSN for authentication and profile retrieval. This segmentation allows the system to maintain security against snooping while enabling authentication operations, as the secondary identifier can be used in place of the NAI for these functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication server acts as a mediator that maps the anonymous secondary identifier back to the primary NAI. When the PDSN needs to retrieve user profiles or perform authentication, it uses the secondary identifier, and the authentication server translates this to the appropriate NAI for profile retrieval, thus maintaining both security and operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a PMIPv4 tunnel is used between eBS and AGW, then secure communication can be established, but the MN-HA key distribution to SRNC and AGW becomes complex

Engineering Contradiction:
Improvecommunication securityVSAvoidkey distribution system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server serves as an intermediary for MN-HA key distribution. Instead of directly distributing keys between multiple entities (eBS, AGW, SRNC), the authentication server receives the MN-HA key from the access terminal and then distributes it to the appropriate network entities. This centralizes the key management function and simplifies the overall key distribution architecture while maintaining secure PMIPv4 tunnel communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11463874B2User profile, policy, and PMIP key distribution in a wireless communication network
Publication Date: 2022.10.04 QUALCOMM INC
  • US11463874B2 patent drawing
  • US11463874B2 patent drawing
  • US11463874B2 patent drawing

AI summary

An authentication server may be adapted to (a) authenticate an authentication peer seeking to establish communications via a first network access node; (b) retrieve user profile information associated with the authentication peer; and/or (c) send the user profile information to a network gateway node that facilitates communication services for the authentication peer. A PMIP network node may be adapted to (a) provide wireless network connectivity to an authentication peer via a first network access node; (b) provide a PMIP key to both ends of a PMIP tunnel between the first network access node and a PMIP network node used to provide communications to the authentication peer; (c) provide the PMIP key to a first authenticator associated the first network access node; (d) receive a request at the PMIP network node from a requesting entity to reroute communications for the authentication peer; and/or (e) verify whether the requesting entity knows the PMIP key.