Certificate Issuing for Roaming Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods fail to enable a terminal device to connect to a communication service on a different network using its original communication ID, especially when the device is roaming, and require direct connections between network service authentication devices and certificate issuing devices, which is impractical for separately managed systems.
Innovation Solution
A certificate authentication method that allows a terminal device to connect to a second network by transmitting a certificate issue request to a certificate issuing device, which checks the communication ID's availability and generates a certificate with a validity period, enabling authentication even when the original communication ID cannot be used, by cooperating with communication ID and sub ID managing entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a terminal device uses its original communication ID to access a communication service, then the user can securely use the service on the original network, but the user cannot use the service when roaming on a different network or when the original communication ID cannot be used
Solution Approach 1:
The patent introduces a certificate as an intermediary credential that mediates between the terminal device and the communication service. The certificate contains the authentication result and allows the terminal to prove its identity on different networks without relying on the original communication ID, thus resolving the contradiction between network adaptability and service reliability
Solution Approach 2:
The patent performs authentication in advance on the original network and stores the authentication result in a certificate. This preliminary authentication action allows the terminal to access services on different networks without performing authentication again, solving the problem of service accessibility when roaming
2Adaptability or versatility
If a digital certificate is issued to enable authentication on a different network, then the terminal can access services when roaming, but the system requires direct connections between network service authentication devices and certificate issuing devices which is impractical for separately managed systems
Solution Approach 1:
The terminal device acts as an intermediary that collects authentication results from different network service authentication devices and obtains certificates from certificate issuing devices. This eliminates the need for direct connections between authentication devices and certificate issuing devices, resolving the contradiction between roaming capability and system complexity
Solution Approach 2:
The patent segments the authentication system into independent components: network service authentication devices that authenticate terminals, certificate issuing devices that issue certificates, and terminals that coordinate between them. This segmentation allows each component to be independently managed while achieving seamless roaming authentication
Data Source
AI summary
A terminal device 4 transmits a certificate issue request including a communication ID thereof and a sub ID to a certificate issuing device 7 via a NW1. The certificate issuing device 7 inquires of a communication ID checking device 5 whether or not the communication ID included in the certificate issue request is in use or not and inquires of a communication ID/sub ID checking device 6 whether or not the communication ID and the sub ID are associated with each other. If both the check results are OK, the certificate issuing device 7 generates a certificate including the ID of the certificate issuing device 7, the communication ID, the sub ID and a validity period and transmits the certificate to the terminal device 4. In this way, a certificate with a short validity period can be issued only based on the access to the NW1 using the communication ID and the sub ID.