Binding Subscriber and Device Authentication for Wireless Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern wireless networks face vulnerabilities where subscriber security credentials can be transferred from authenticated devices to unauthorized ones, allowing unauthorized access to network services, particularly in relay nodes and machine-to-machine (M2M) devices, without physical access, necessitating enhanced security measures to prevent misuse.
Innovation Solution
A method and apparatus that bind subscriber authentication and device authentication to generate a security key, using a combination of keys from both processes, along with network and device nonces, to secure communications, ensuring that the security key is generated separately by the device and network entity to prevent over-the-air transmission, and utilizing challenge-response exchanges and cryptographic key agreements to authenticate devices within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If subscriber security credentials are stored in a removable module that can be transferred between devices, then ease of operation and device interchangeability are improved, but security vulnerability increases as unauthorized devices can access network services
Solution Approach 1:
The patent combines subscriber authentication credentials with device authentication credentials into a single bound authentication mechanism. The security key is generated as a function of both subscriber credentials (from AKA authentication) and device credentials (from device authentication), merging two separate authentication systems into one unified security framework that prevents credential transfer between devices.
2Reliability
If device authentication is implemented separately from subscriber authentication, then device control and network security are improved, but authentication complexity and processing overhead increase
Solution Approach 1:
The patent merges device authentication and subscriber authentication into a single bound authentication process where both credential types are required to generate the security key. This approach maintains separate device control capabilities while reducing overall authentication complexity by binding both credentials together in one unified security context rather than requiring separate authentication flows.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
An authentication method is provided between a device (e.g., a client device or access terminal) and a network entity. A removable storage device may be coupled to the device and stores a subscriber-specific key that may be used for subscriber authentication. A secure storage device may be coupled to the device and stores a device-specific key used for device authentication. Subscriber authentication may be performed between the device and a network entity. Device authentication may also be performed of the device with the network entity. A security key may then be generated that binds the subscriber authentication and the device authentication. The security key may be used to secure communications between the device and a serving network.