Biometric Authentication in Wireless Access Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication mechanisms in wireless networks rely on identity information stored in terminal devices, which can be insecure and prone to unauthorized access, lacking advanced security features to ensure robust user identification.

Innovation Solution

Implementing biometric data-based authentication in wireless access networks, where user biometric data such as fingerprints, retina scans, or voice samples are stored and used for authentication, enabling secure connection establishment and access management through network elements like the Home Subscriber Server (HSS) and authentication servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication mechanisms using identity information stored in terminal devices are used, then the authentication process is simple and device complexity is low, but security reliability is insufficient and prone to unauthorized access

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary component between the terminal device and the network. The authentication server receives authentication requests, retrieves biometric data from the HSS, performs verification, and returns authentication results. This intermediary architecture enhances security by centralizing the authentication logic and using secure biometric verification, while the terminal device itself remains relatively simple without needing complex local authentication processing capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric data-based authentication is implemented, then user identification uniqueness and security are enhanced, but the complexity of the authentication system increases due to additional network elements and data management requirements

Engineering Contradiction:
Improveuser identification securityVSAvoidauthentication infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing HSS (Home Subscriber Server) infrastructure in wireless networks to store and manage biometric data. The HSS, which already serves as a central repository for subscriber information, is extended to also store biometric templates. This multi-functional use of the HSS avoids the need for completely separate biometric storage systems, thereby enhancing security through biometric authentication while minimizing the increase in overall system complexity by reusing existing network elements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If biometric data is stored and transmitted through the network, then authentication robustness is improved, but the risk of data exposure and unauthorized access during transmission increases

Engineering Contradiction:
Improveauthentication robustnessVSAvoiddata exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and separates the biometric data storage function from the terminal device and places it in the secure network environment (HSS). The terminal device only stores minimal authentication credentials and retrieves biometric data from the HSS during authentication. This extraction of sensitive biometric data from the potentially less-secure terminal device to the more secure network infrastructure reduces the risk of data exposure during transmission and storage, while still enabling robust authentication when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11265710B2User authentication in wireless access network
Publication Date: 2022.03.01 NOKIA SOLUTIONS & NETWORKS OY
  • US11265710B2 patent drawing
  • US11265710B2 patent drawing
  • US11265710B2 patent drawing

AI summary

This document discloses a solution for enabling biometric authentication of a station. According to an aspect, the solution comprises transmitting, from the station, a trigger to include biometric data of a user of the station in authentication; a logic at a network node to handle the trigger and cause execution of an authentication procedure that employs the biometric data when performing said authentication procedure in a wireless access network; and indicating a result of the authentication to the station.