Deployable Wireless Network Local Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Public safety agencies face challenges in establishing secure data networks in areas without fixed network services, as existing authentication methods require access to home subscriber servers, which is not feasible in remote or disaster-stricken locations, posing security risks and practicality issues for multi-agency wireless device connectivity.

Innovation Solution

Implementing a deployable wireless communications network with a local authentication database and a mobile management entity configured as an extensible authentication protocol (EAP) authenticator, allowing wireless devices to connect and authenticate without relying on an auxiliary network, by using a local home subscriber server and generating a subscription profile with a shared symmetric key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing authentication methods (AKA authentication) are used, then wireless devices can be authenticated with home subscriber servers, but access to home subscriber servers is required which is not feasible in remote areas or disaster-stricken locations

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidoperational feasibility in remote areas
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an auxiliary network as an intermediary component that enables authentication in remote areas. The auxiliary network includes a local home subscriber server that can authenticate wireless devices without requiring direct access to the original home subscriber server. This mediator allows the authentication process to function independently in isolated locations while maintaining security through encrypted communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into multiple independent components: the original home subscriber server, the auxiliary network with its own local home subscriber server, and the wireless devices. This segmentation allows the authentication function to be distributed across different locations, enabling remote authentication capabilities while maintaining the integrity of the original authentication authority.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If sensitive security information is replicated on local home subscriber server, then authentication can proceed without home subscriber server access, but security risks increase

Engineering Contradiction:
Improveauthentication capability in isolated locationsVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a controlled copying mechanism where the auxiliary network's home subscriber server receives and stores copies of authentication data from the original home subscriber server. These copies are encrypted and transmitted through secure channels. The local server can then perform authentication using these copied credentials without requiring continuous connection to the original server, enabling operation in isolated locations while maintaining security through encrypted data transmission and storage.

Inventive Principle:
Principle #26Copying

3Device complexity

If deployable wireless communications network is deployed without auxiliary network, then network complexity is reduced, but wireless devices from multiple agencies cannot connect securely

Engineering Contradiction:
Improvenetwork structure complexityVSAvoidmulti-agency device connectivity
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The auxiliary network's home subscriber server is designed with universal authentication capabilities that can handle wireless devices from multiple different agencies. It can store and manage authentication credentials for various agencies' devices and perform authentication for any of them. This multi-functional design allows a single deployable network to serve multiple agencies without requiring separate authentication infrastructure for each agency, thereby maintaining relatively simple network structure while achieving broad compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20180220471A1Methods and systems for connecting a wireless communications device to a deployable wireless communications network
Publication Date: 2018.08.02 MOTOROLA SOLUTIONS INC
  • US20180220471A1 patent drawing
  • US20180220471A1 patent drawing
  • US20180220471A1 patent drawing

AI summary

Methods and systems for connecting a wireless communications device to a deployable wireless communications network. The method includes receiving, from the wireless communications device via a mobile management entity (MME) configured to operate as an extensible authentication protocol (EAP) authenticator, an extensible authentication protocol packet. The method further includes authenticating the wireless communications device based on the extensible authentication protocol packet. The method further includes establishing a first wireless connection between the wireless communications device and a deployable subscription bootstrapping service of the deployable wireless communications network. The method further includes generating a subscription profile for the wireless communications device, and communicating the subscription profile to the wireless communications device via the first wireless connection. The method further includes discontinuing the first wireless connection, and establishing a second wireless connection between the wireless communications device and the deployable wireless communications network using the subscription profile.