Closed Subscriber Group Authentication for Enterprise Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for authenticating client devices to enterprise networks are burdensome and inefficient, requiring users to manually input credentials each time they access the network, which can be frustrating and drain device battery life.

Innovation Solution

Implementing a closed subscriber group (CSG) authentication method that automatically verifies client devices using existing identity credentials, such as SIM card credentials, to grant access to enterprise networks without user input, leveraging EAP-SIM mechanisms for secure authentication and key distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual credential entry is required for network access, then authentication security is improved, but user convenience deteriorates and battery life is reduced

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring client devices with subscription information and closed subscriber group (CSG) identifiers before network access is needed. The authentication credentials are stored in advance on the device, allowing automatic authentication without requiring users to manually enter credentials at the time of network access, thus improving convenience while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service authentication where the client device automatically performs authentication against the access controller using its pre-stored subscription information and CSG identifiers. The device autonomously determines network accessibility and performs authentication without user intervention, eliminating the need for manual credential entry while maintaining secure access

Inventive Principle:
Principle #25Self-service

2Reliability

If manual credential entry is required for network access, then authentication control is improved, but authentication time increases and productivity decreases

Engineering Contradiction:
Improveauthentication controlVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-configuring client devices with subscription information and closed subscriber group (CSG) identifiers before network access is needed. The authentication credentials are stored in advance on the device, allowing automatic authentication without requiring users to manually enter credentials at the time of network access, thus improving convenience while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements rapid authentication by skipping the manual credential entry step. The client device uses its pre-stored subscription information and CSG identifiers to automatically authenticate against the access controller, rushing through the authentication process without the time-consuming manual input step, thereby improving productivity while maintaining control

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11546339B2Authenticating client devices to an enterprise network
Publication Date: 2023.01.03 CISCO TECHNOLOGY INC
  • US11546339B2 patent drawing
  • US11546339B2 patent drawing
  • US11546339B2 patent drawing

AI summary

Various implementations disclosed herein provide a method for authenticating users to an enterprise network using closed subscriber groups. The method includes determining whether the client device is associated with a subscriber group that corresponds to the enterprise network. The method further includes granting the client device access to the enterprise network in response to determining that the client device is associated with the subscriber group that corresponds to the enterprise network.