Distributed Authentication Centers for Mobile Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 2G/3G/4G security protection modes in mobile communications networks are inflexible, requiring all root keys to be stored on a core node (HSS), which increases system complexity and cannot satisfy the authentication flexibility needs of mass devices, especially in future mobile communications networks with diverse security requirements.

Innovation Solution

An authentication method that allows user equipment to authenticate without involving the Home Subscriber Server (HSS), using a process where one user equipment sends a random parameter to another, generating authentication features based on user identifiers and random parameters, and verifying these features using message authentication codes, ciphertext, or digital signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all root keys are stored on a core node (HSS) to ensure security, then security protection is provided, but system complexity increases and authentication flexibility cannot be satisfied

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into multiple authentication centers (AC1, AC2, etc.) instead of relying on a single HSS. Each authentication center stores only a portion of user authentication information, distributing the security burden and reducing system complexity. User equipment can be authenticated by multiple different authentication centers, eliminating the need for all root keys to be centralized in one location.

Inventive Principle:
Principle #1Segmentation

2Reliability

If all root keys are stored on a core node (HSS) to ensure security, then security protection is provided, but authentication flexibility for mass devices cannot be satisfied

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the authentication functionality across multiple authentication centers, allowing different user equipment to be authenticated by different authentication centers. This segmentation enables flexible authentication arrangements where mass devices can be authenticated without requiring HSS participation, while still maintaining security through distributed key storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authentication centers as intermediary nodes between user equipment and the network. These authentication centers act as mediators that can perform authentication independently of the HSS, enabling flexible authentication scenarios while maintaining security through the distributed architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11228442B2Authentication method, authentication apparatus, and authentication system
Publication Date: 2022.01.18 HUAWEI TECH CO LTD
  • US11228442B2 patent drawing
  • US11228442B2 patent drawing
  • US11228442B2 patent drawing

AI summary

An authentication method, an authentication apparatus, and an authentication system for the communications field are described. The authentication includes receiving, by a communications network element, a request from a user equipment (UE) comprising a first identifier that is an international mobile subscriber identity (IMSI). The communication network element, in response to the request, sends the first identifier to a home subscriber server. The communications network element, upon authenticating the UE successfully, sends a second identifier to a key management center (KMS) to facilitate the KMS generating a subscriber private key corresponding to the second identifier and sending the subscriber private key to the communications network element. The communications network element thereafter sends the subscriber private key to the UE.