Communication Device Authentication Verification for Untrusted Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, such as WiMAX and LTE, are vulnerable to security and privacy-related attacks due to vulnerabilities in their network access procedures, where devices may be exposed to unauthorized access if authentication steps are incomplete or not followed correctly.

Innovation Solution

A communication device is designed to detect when authentication is not supported by the network and terminate the communication link promptly, ensuring secure access by transmitting a registration request and a disconnection request when an authentication response is not received, thereby preventing exposure to untrusted networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network access procedure follows standard protocols without verification, then connection establishment is fast and simple, but security and privacy are compromised due to unauthorized access

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication verification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing authentication verification during the registration phase before full network access is granted. The communication device checks whether the network supports authentication protocols in advance, and only completes registration if authentication is supported. This prevents unauthorized access early in the connection process without requiring complex ongoing authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the registration message exchange as an intermediary mechanism to verify authentication support. Instead of implementing a separate complex authentication protocol, the device uses the existing registration communication channel to exchange authentication capability information between the network and the device, simplifying the verification process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If authentication verification is implemented, then security against unauthorized access is improved, but the network access procedure becomes more complex and time-consuming

Engineering Contradiction:
Improvesecurity attacks preventionVSAvoidnetwork access time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The authentication verification is performed as a preliminary check during the registration phase, before any sensitive network operations begin. By checking authentication support early in the message exchange sequence, the patent prevents security attacks without adding significant time to the overall access procedure, as the verification is integrated into existing registration timing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a partial verification approach by checking only the essential authentication capability during registration, rather than performing complete authentication sequences. This partial action is sufficient to prevent unauthorized access to networks that don't support authentication, while avoiding the time cost of full authentication protocols for routine connections.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the device waits for authentication request after registration, then proper authentication sequence is maintained, but the device remains vulnerable to unauthorized access if authentication is not supported

Engineering Contradiction:
Improveauthentication completenessVSAvoidconnection establishment simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs authentication capability verification as a preliminary action during the registration message exchange, before the device waits for or sends authentication requests. This ensures that if the network doesn't support authentication, the device detects this early and terminates the connection attempt, maintaining both authentication completeness and operational simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The communication device autonomously verifies authentication support without requiring the network to initiate authentication requests. The device independently checks authentication capability during registration and makes the decision to proceed or terminate, simplifying the interaction while ensuring authentication completeness.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9060028B1Method and apparatus for rejecting untrusted network
Publication Date: 2015.06.16 SPRINT SPECTRUM LLC
  • US9060028B1 patent drawing
  • US9060028B1 patent drawing
  • US9060028B1 patent drawing

AI summary

A method of accessing a communication system and a communication device for performing the same are disclosed. The method includes transmitting, by the communication device to a node of the communication system through a communication link between the communication device and the node, a registration request to register with the communication system, transmitting, by the communication device to the node, a request to disconnect the communication link, when receiving from the communication system a registration response in response to the registration request before receiving an authentication request from the communication system.