Femtocell Authentication via IMS Secure Entities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Femtocells, used in distributed wireless communication networks, lack secure storage for secret keys, making them susceptible to fraud and unauthorized access, which complicates authenticating mobile units and ensuring secure communication.
Innovation Solution
Implementing a method where a femtocell operates within an Internet Protocol Multimedia Subsystem (IMS) network, using a global challenge and unique challenge/response pairs to authenticate mobile units, with secure entities in the IMS network verifying authentication responses to ensure secure communication links.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If femtocells are deployed in distributed locations to provide wireless connectivity, then coverage and accessibility are improved, but security and reliability deteriorate due to lack of secure storage for secret keys
Solution Approach 1:
The patent introduces secure entities in the network as intermediaries between the unsecured femtocell and the authentication process. These secure entities perform the critical authentication functions that would otherwise need to reside in the unsecured femtocell, thereby enabling distributed deployment while maintaining security.
Solution Approach 2:
The authentication functionality is extracted from the femtocell and placed in secure network entities. By removing the security-critical components from the unsecured femtocell environment, the system can operate in distributed locations without compromising authentication reliability.
2Loss of time
If authentication is performed at the femtocell level, then response time is reduced, but security deteriorates due to unsecured storage of secret keys
Solution Approach 1:
Secure entities act as intermediaries that receive authentication requests from femtocells, perform the security-critical authentication operations, and return results to the femtocell. This allows the femtocell to maintain fast response times while the secure entities ensure key storage security.
Solution Approach 2:
The authentication process is segmented into two parts: rapid authentication request handling at the unsecured femtocell and secure authentication execution at protected network entities. This segmentation allows optimization of both response time and security without compromise.
3Ease of operation
If global challenges are used for authentication, then ease of operation is improved, but security deteriorates due to susceptibility to fraud
Solution Approach 1:
Secure entities serve as intermediaries that receive global challenges from the network and generate corresponding authentication responses. This allows the simple global challenge mechanism to remain easy to operate while the secure entities prevent fraud by ensuring proper authentication key usage.
Solution Approach 2:
The system implements feedback mechanisms where secure entities verify authentication responses and provide feedback to both the mobile unit and the network. This feedback loop detects and prevents fraudulent authentication attempts while maintaining the simplicity of global challenge-based operation.
Data Source
AI summary
The present invention provides a method involving a femtocell in communication with an Internet Protocol Multimedia Subsystem (IMS) network. In one embodiment, the femtocell operates according to code division multiple access (CDMA) standards. The method includes receiving, from the femtocell and at a first secure entity in the IMS network, first authentication information generated by the mobile unit using a first random number broadcast by the femtocell in a global challenge. The method also includes receiving, from a second secure entity in the secure network, at least one security key formed based on the global challenge and second authentication information for uniquely challenging the mobile unit. In one embodiment, the second secure entity is a CDMA-based authentication server. The method further includes providing the security key(s) to the femtocell in response to authenticating the mobile unit based upon the second authentication information.


