Femtocell Authentication via IMS Secure Entities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Femtocells, used in distributed wireless communication networks, lack secure storage for secret keys, making them susceptible to fraud and unauthorized access, which complicates authenticating mobile units and ensuring secure communication.

Innovation Solution

Implementing a method where a femtocell operates within an Internet Protocol Multimedia Subsystem (IMS) network, using a global challenge and unique challenge/response pairs to authenticate mobile units, with secure entities in the IMS network verifying authentication responses to ensure secure communication links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If femtocells are deployed in distributed locations to provide wireless connectivity, then coverage and accessibility are improved, but security and reliability deteriorate due to lack of secure storage for secret keys

Engineering Contradiction:
Improvecoverage areaVSAvoidauthentication security
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent introduces secure entities in the network as intermediaries between the unsecured femtocell and the authentication process. These secure entities perform the critical authentication functions that would otherwise need to reside in the unsecured femtocell, thereby enabling distributed deployment while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication functionality is extracted from the femtocell and placed in secure network entities. By removing the security-critical components from the unsecured femtocell environment, the system can operate in distributed locations without compromising authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of time

If authentication is performed at the femtocell level, then response time is reduced, but security deteriorates due to unsecured storage of secret keys

Engineering Contradiction:
Improveauthentication response timeVSAvoidkey storage security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

Secure entities act as intermediaries that receive authentication requests from femtocells, perform the security-critical authentication operations, and return results to the femtocell. This allows the femtocell to maintain fast response times while the secure entities ensure key storage security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into two parts: rapid authentication request handling at the unsecured femtocell and secure authentication execution at protected network entities. This segmentation allows optimization of both response time and security without compromise.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If global challenges are used for authentication, then ease of operation is improved, but security deteriorates due to susceptibility to fraud

Engineering Contradiction:
Improveauthentication simplicityVSAvoidfraud susceptibility
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Secure entities serve as intermediaries that receive global challenges from the network and generate corresponding authentication responses. This allows the simple global challenge mechanism to remain easy to operate while the secure entities prevent fraud by ensuring proper authentication key usage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where secure entities verify authentication responses and provide feedback to both the mobile unit and the network. This feedback loop detects and prevents fraudulent authentication attempts while maintaining the simplicity of global challenge-based operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8457597B2Method for authenticating a mobile unit attached to a femtocell that operates according to code division multiple access
Publication Date: 2013.06.04 ALCATEL LUCENT SA
  • US8457597B2 patent drawing
  • US8457597B2 patent drawing
  • US8457597B2 patent drawing

AI summary

The present invention provides a method involving a femtocell in communication with an Internet Protocol Multimedia Subsystem (IMS) network. In one embodiment, the femtocell operates according to code division multiple access (CDMA) standards. The method includes receiving, from the femtocell and at a first secure entity in the IMS network, first authentication information generated by the mobile unit using a first random number broadcast by the femtocell in a global challenge. The method also includes receiving, from a second secure entity in the secure network, at least one security key formed based on the global challenge and second authentication information for uniquely challenging the mobile unit. In one embodiment, the second secure entity is a CDMA-based authentication server. The method further includes providing the security key(s) to the femtocell in response to authenticating the mobile unit based upon the second authentication information.