Binding Subscriber and Device Authentication for Wireless Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern wireless networks face vulnerabilities where subscriber security credentials can be transferred from authenticated devices to unauthorized ones, allowing unauthorized access to network services, particularly in relay nodes and machine-to-machine (M2M) devices, without physical access, necessitating enhanced security measures to prevent misuse.

Innovation Solution

A method and apparatus that bind subscriber authentication and device authentication to generate a security key, using a combination of keys from both processes, along with network and device nonces, to secure communications, ensuring that the security key is generated separately by the device and network entity to prevent over-the-air transmission, and utilizing challenge-response exchanges and cryptographic key agreements to authenticate devices within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If subscriber security credentials are stored in a removable module that can be transferred between devices, then ease of operation and device interchangeability are improved, but security vulnerability increases as unauthorized devices can access network services

Engineering Contradiction:
Improvedevice interchangeabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines subscriber authentication credentials with device authentication credentials into a single bound authentication mechanism. The security key is generated as a function of both subscriber credentials (from AKA authentication) and device credentials (from device authentication), merging two separate authentication systems into one unified security framework that prevents credential transfer between devices.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If device authentication is implemented separately from subscriber authentication, then device control and network security are improved, but authentication complexity and processing overhead increase

Engineering Contradiction:
Improvedevice controlVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges device authentication and subscriber authentication into a single bound authentication process where both credential types are required to generate the security key. This approach maintains separate device control capabilities while reducing overall authentication complexity by binding both credentials together in one unified security context rather than requiring separate authentication flows.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2583479B1Method and apparatus for binding subscriber authentication and device authentication in communication systems
Publication Date: 2020.01.01 QUALCOMM INC
  • EP2583479B1 patent drawingFigure 1
  • EP2583479B1 patent drawingFigure 2
  • EP2583479B1 patent drawingFigure 3A

AI summary

An authentication method is provided between a device (e.g., a client device or access terminal) and a network entity. A removable storage device may be coupled to the device and stores a subscriber-specific key that may be used for subscriber authentication. A secure storage device may be coupled to the device and stores a device-specific key used for device authentication. Subscriber authentication may be performed between the device and a network entity. Device authentication may also be performed of the device with the network entity. A security key may then be generated that binds the subscriber authentication and the device authentication. The security key may be used to secure communications between the device and a serving network.