Femtocell Authentication via Dual Gateway IP Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current femtocell authentication methods in wireless telecommunications networks are vulnerable to compromised femtos gaining access by altering their identity, leading to potential eavesdropping and security breaches, as they do not verify payload information and can register with different identities post-authentication.

Innovation Solution

A method involving a security gateway and femto-gateway that verifies the source IP address of packets by checking it against an expected address or range, ensuring authenticity by using a database mapping and secondary authorization to prevent unauthorized access, even when gateways are separate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If femtocell base stations use separate security gateway and femto-gateway for authentication, then network security is improved, but device complexity and authentication process complexity increase

Engineering Contradiction:
Improvenetwork securityVSAvoidgateway structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is divided into two separate gateways: security gateway for initial authentication and IP tunnel establishment, and femto-gateway for secondary authorization and registration. This segmentation allows each gateway to have specialized functions, improving security through layered verification while maintaining manageable complexity through clear functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security gateway acts as an intermediary between the femtocell base station and the femto-gateway. It performs initial authentication, establishes secure IP tunnels, and forwards authenticated connections to the femto-gateway. This intermediary role enables the system to maintain security checks at multiple levels without requiring direct complex interactions between all components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If femtocell base stations perform plug-and-play deployment with automatic integration, then ease of operation is improved, but security vulnerability increases due to lack of identity verification

Engineering Contradiction:
Improvedeployment simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Before allowing plug-and-play deployment, the security gateway performs preliminary authentication by verifying the femtocell base station's identity and establishing secure IP tunnels. The femto-gateway then performs secondary authorization by checking the source IP address against the authenticated identity. These preliminary security actions occur automatically during deployment, maintaining ease of operation while ensuring robust security verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the security gateway provides authentication status information to the femto-gateway, which then uses this feedback to make authorization decisions. The femto-gateway checks the source IP address against the authenticated identity information received from the security gateway, creating a feedback loop that ensures security verification without complicating the deployment process for users.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9473934B2Wireless telecommunications network, and a method of authenticating a message
Publication Date: 2016.10.18 NOKIA TECHNOLOGIES OY
  • US9473934B2 patent drawing
  • US9473934B2 patent drawing
  • US9473934B2 patent drawing

AI summary

A method is provided of authenticating a message from a femtocell base station in a wireless telecommunications network comprising a security gateway and a femto-gateway. The method comprising the steps of: checking by the security gateway that a source IP address in the message from the femtocell base station accords with that expected from that femtocell base station, and checking by the femto-gateway that the source IP address in the message accords with that expected from that femtocell base station by inspecting a database relating a femtocell base station identifier to source IP address data.