Disaster Roaming Authentication Using Pre-Configured Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, especially during disaster conditions, user equipment (UE) faces challenges in authenticating and registering with a secondary network when primary network coverage is lost, particularly when there are no pre-set roaming interfaces between networks, leading to potential security risks and limited access to essential services.

Innovation Solution

The method involves a UE transmitting a registration request with an indication for capability to a secondary network, which then requests authentication procedures, allowing for registration based on stored credentials, even in the absence of primary authentication, and configuring network entities to broadcast availability for disaster roaming, using pre-configured certificates for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If UE attempts to register with secondary network during disaster conditions without pre-set roaming interfaces, then service access is enabled, but security risks increase due to lack of established authentication protocols

Engineering Contradiction:
Improveservice access capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring authentication credentials ( certificates, keys, or other authentication data) in the UE before disaster conditions occur. This allows the UE to immediately perform authentication with secondary networks during disasters without requiring pre-set roaming interfaces, thus enabling service access while maintaining security through pre-validated credentials.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional authentication procedures are used in disaster roaming scenarios, then security is maintained through established protocols, but service access is limited due to lack of roaming agreements between networks

Engineering Contradiction:
ImprovesecurityVSAvoidservice access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent uses pre-configured authentication credentials as an intermediary mechanism that enables direct authentication between UE and secondary networks without requiring traditional roaming interfaces or agreements. These credentials act as a mediator that bypasses the need for established roaming relationships while maintaining security through cryptographically validated authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If UE stores multiple authentication credentials for different networks, then authentication flexibility increases, but device complexity increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidcredential management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the UE to automatically select and use appropriate pre-configured credentials based on the target network identifier. The device autonomously matches the secondary network it needs to register with the corresponding pre-stored credential set, eliminating the need for complex manual credential management or external authentication broker assistance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240187856A1Registration authentication based on a capability
Publication Date: 2024.06.06 LENOVO (SINGAPORE) PTE LTD
  • US20240187856A1 patent drawing
  • US20240187856A1 patent drawing
  • US20240187856A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for registration authentication based on a capability. One method (700) includes receiving (702), at a second network device from a first network device, an indication for a capability for a registration. The method (700) includes transmitting (704), to a third network device, a first request for a type of authentication procedure for the registration. The method (700) includes transmitting (706), to a remote unit, a second request. The second request corresponds to the type of authentication procedure for the registration. The method (700) includes receiving (708), from the remote unit, a response to the second request. The response corresponds to a stored credential in the remote unit.