Network Access Authentication Using Encrypted IMSI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing network access authentication process does not define how to proceed when the user equipment alias identifier in the user equipment is asynchronous with the user equipment alias identifier in the home network.

Innovation Solution

A network access authentication method that involves receiving an authentication request message from a serving network, determining if the local user equipment alias identifier is asynchronous with the user equipment alias identifier generated by the user equipment, and if so, obtaining an encrypted International Mobile Subscriber Identification Number (IMSI) for performing network access authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network uses user equipment alias identifier for authentication, then user privacy is protected, but authentication reliability fails when identifiers are asynchronous

Engineering Contradiction:
Improveauthentication reliabilityVSAvoididentifier synchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces encrypted IMSI as an intermediary identifier when the alias identifier synchronization fails. Instead of directly using the alias identifier for authentication, the system falls back to the encrypted IMSI which serves as a mediator to establish authentication trust between the user equipment and serving network, resolving the reliability issue without requiring complex synchronization mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the serving network checks whether the user equipment alias identifier is synchronous with the home network's alias identifier. Based on this feedback, the system dynamically selects the appropriate authentication method - using alias identifier when synchronous and encrypted IMSI when asynchronous, thereby maintaining authentication reliability under varying conditions

Inventive Principle:
Principle #23Feedback

2Reliability

If the network falls back to encrypted IMSI for authentication, then authentication reliability is maintained, but authentication time increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-establishing the mapping relationship between alias identifiers and encrypted IMSIs in the home network, and by having the serving network proactively check for identifier synchronization before authentication. This preliminary preparation allows the system to use the faster alias identifier authentication path when conditions permit, minimizing the impact of fallback to encrypted IMSI authentication

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3826339B1Network access authentication method and device
Publication Date: 2025.05.14 ZTE CORP
  • EP3826339B1 patent drawingFigure 1
  • EP3826339B1 patent drawingFigure 2
  • EP3826339B1 patent drawingFigure 3

AI summary

The present invention relates to a method for wireless communication, comprising receiving, by a second serving network, an attach request originated from a user equipment, the attach request carrying a temporary identifier; transmitting, by the second serving network, a request message to a first serving network that previously served the user equipment to obtain a user context from the first serving network according to the temporary identifier carried in the attach request; receiving, by the second serving network, a response message from the first serving network indicating a failure in retrieving the user context; transmitting, by the second serving network in response to the failure, an identity request message to the user equipment, wherein the identity request message includes an identity type indicating an encrypted subscription identity; and receiving, by the second serving network, an identity response from the user equipment including the encrypted subscription identity.