CDMA2000 Authentication Server Generating GSM Vectors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods like EAP SIM and EAP AKA are limited to networks with GSM or UMTS infrastructure, making it difficult to implement them in CDMA2000 networks for WLAN-CDMA2000 interworking scenarios.

Innovation Solution

An authentication server within the CDMA2000 network generates GSM or UMTS-like authentication vectors using a root secret key, enabling EAP SIM or EAP AKA authentication methods for user terminals connected to non-CDMA2000 networks, such as WLAN networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAP SIM or EAP AKA authentication methods are used, then security and authentication capability are improved, but network compatibility is worsened because these methods are limited to GSM or UMTS infrastructure and cannot be implemented in CDMA2000 networks

Engineering Contradiction:
Improveauthentication capabilityVSAvoidnetwork compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an authentication server as an intermediary component in the CDMA2000 network that generates GSM/UMTS-like authentication vectors (triplets or quintets) using a root secret key. This intermediary enables the CDMA2000 network to provide authentication services compatible with EAP SIM and EAP AKA methods without requiring actual GSM or UMTS infrastructure, thus resolving the network compatibility issue while maintaining security capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameters by using a root secret key stored in the CDMA2000 network's authentication server to generate authentication vectors that mimic GSM/UMTS protocols. This parameter transformation allows CDMA2000 terminals to participate in GSM/UMTS-like authentication procedures, achieving cross-network compatibility without modifying the terminal hardware or requiring dual network infrastructure.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If CDMA2000 network uses native authentication methods, then network simplicity is improved, but adaptability to non-CDMA2000 networks is worsened

Engineering Contradiction:
Improvenetwork structureVSAvoidWLAN-CDMA2000 interworking
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The authentication server in the CDMA2000 network is designed with multi-functionality, serving both native CDMA2000 authentication and generating GSM/UMTS-like authentication vectors for WLAN interworking. This universal authentication mechanism allows the same network infrastructure to support multiple network types and authentication protocols, enabling seamless WLAN-CDMA2000 interworking without requiring separate authentication systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7546459B2GSM-like and UMTS-like authentication in a CDMA2000 network environment
Publication Date: 2009.06.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US7546459B2 patent drawing
  • US7546459B2 patent drawing
  • US7546459B2 patent drawing

AI summary

An authentication server (e.g., AAA server) is described herein which is located in a CDMA2000 network and used to authenticate a user terminal that is connected to a non-CDMA2000 network. The authentication server receives an access request for authenticating the user terminal connected to the non-CDMA2000 network. Then, it obtains a root secret key shared between the user terminal and the CDMA2000 network and generates a GSM or UMTS-like authentication vector which is used to authenticate the user terminal according to a GSM or UMTS-like authentication method. The access of the terminal to the non-CDMA2000 network is granted upon successful authentication. According to embodiments of the invention, the non-CDMA2000 network can be a WLAN network, and the authentication methods used can be EAP SIP or EAP AKA. The present invention allows one to use authentication servers that were originally intended for WLAN-3GPP interworking scenarios also in WLAN-CDMA2000 network interworking.