Dual-Phase Authentication for Emergency Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face challenges in providing emergency access to unsubscribed or unauthorized users, as they require improved architectures to support new features like emergency services and roaming access, which are not adequately addressed by current authentication methods.

Innovation Solution

A network system that grants users restricted access at a reduced rate without initial authentication, with subsequent full access upon successful authentication, using separate communications for user and device or line authentication, and employing access nodes to authenticate based on the type of access network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is required for network access, then security is improved, but emergency access for unauthorized users deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidemergency access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments authentication into two distinct phases: device authentication (for network access) and user authentication (for service access). This allows emergency services to bypass user authentication and access the network through device authentication alone, while maintaining security for normal operations where both authentications are required.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs device authentication in advance as a preliminary step, granting temporary network access before user authentication is completed. This preliminary action enables emergency services to access the network immediately without waiting for user identification, while full service access is granted after successful user authentication.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If device authentication is used, then access is granted quickly, but user identity verification deteriorates

Engineering Contradiction:
Improveaccess speedVSAvoiduser identity verification
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The authentication process is divided into two independent authentication mechanisms: device authentication (verifying the device/line identity) and user authentication (verifying the user identity). Device authentication provides quick access, while user authentication provides precise identity verification. Both can be performed in parallel or sequence depending on service requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial authentication (device authentication only) when full user verification is not immediately required, such as for emergency services. This partial action enables faster access while the option for complete user verification remains available when needed.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If separate authentication communications are used, then authentication flexibility is improved, but system complexity deteriorates

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs a universal authentication framework that handles both device authentication and user authentication through a unified architecture. The same authentication infrastructure supports multiple authentication types (device-based, user-based, or both), providing flexibility without requiring separate independent systems for each authentication mode.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9112909B2User and device authentication in broadband networks
Publication Date: 2015.08.18 FUTUREWEI TECHNOLOGIES INC
  • US9112909B2 patent drawing
  • US9112909B2 patent drawing
  • US9112909B2 patent drawing

AI summary

A network component comprising at least one processor configured to implement a method comprising granting a user restricted access at a reduced rate without authenticating the user, attempting to authenticate the user, and granting the user unrestricted access at a full rate if the user authentication is successful. Included is a method comprising authenticating a user device, a user line, or both using a first communication, and authenticating a user using a second communication separate from the first communication. Also included is an apparatus comprising an access node (AN) configured to couple to an access network and communicate with a user equipment (UE) via the access network, wherein the UE is authenticated using either line authentication or device authentication based on the access network.