Client Identity Generation via Synchronized Time and Network Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for generating client identities in communication systems, particularly in virtual private networks (VPNs), are complex, costly, and inefficient in terms of network resource usage, and lack sufficient security against unauthorized access.

Innovation Solution

A method that generates client identities using synchronized time information from both the client's timer device and the mobile radio network, combined with cryptographic algorithms and identifiers from both computer and mobile networks, to enhance security and reduce administrative efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional methods are used for generating client identities in VPNs, then authentication and authorization can be performed, but the system complexity and administrative burden increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines mobile network identity mechanisms (HLR, IMSI) with computer network authentication into a unified identity generation system. The mobile network's home location register (HLR) and international mobile subscriber identity (IMSI) are integrated with the authentication, authorization, and accounting (AAA) server to automatically generate computer network identities, eliminating the need for separate identity management systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile network infrastructure is extended to serve dual purposes: traditional mobile communication and computer network authentication. The HLR and AAA server perform both mobile network functions and computer network identity management, allowing the same infrastructure to support multiple authentication scenarios without requiring dedicated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional identity generation methods are used, then client authentication is possible, but network resource consumption and costs increase

Engineering Contradiction:
Improveauthorization securityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system enables self-service authentication by leveraging the mobile terminal's existing SIM card and IMSI. The client automatically generates their computer network identity using their mobile network credentials without requiring manual configuration or additional authentication tokens. The mobile network's existing infrastructure (HLR, AAA server) handles the authentication process automatically based on the client's IMSI.

Inventive Principle:
Principle #25Self-service

3Reliability

If complex identity generation systems are deployed, then security can be maintained, but administrative efforts and operational costs increase

Engineering Contradiction:
Improveaccess control securityVSAvoidadministrative effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically generates and manages computer network identities using the mobile network's existing subscriber data. The HLR and AAA server handle identity creation, updates, and revocation automatically based on the client's IMSI and mobile network subscription status, eliminating the need for manual identity management and reducing administrative overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP1955515B1Generation of client identities in a communication system
Publication Date: 2011.05.11 VODAFONE HOLDING GMBH
  • EP1955515B1 patent drawingFigure 1
  • EP1955515B1 patent drawingFigure 2
  • EP1955515B1 patent drawingFigure 3

AI summary

The invention relates to methods, systems and devices for generating and/or using client identities in a communication system, made up of a computer network with data terminal devices and a cellular mobile radio network with mobile terminals which may be operated therein. The identity of a client is generated using at least one piece of time information (TKlient) synchronised with a piece of time information (TNetz) from the mobile radio network. A particular feature of the invention is the use of such an identity or authentication and/or authorisation of access on a data terminal device to data and/or services on data terminal device in a computer network, which becomes the identity of a client.