Femtocell Authentication via IMS Network Security Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Femtocells, used in distributed wireless communication networks, lack secure storage for secret keys, making them susceptible to fraudulent activities as they are often deployed in unsecured locations, which complicates authentication processes and compromises network security.

Innovation Solution

Implementing a method where a femtocell communicates with an Internet Protocol Multimedia Subsystem (IMS) network using CDMA standards, where the IMS network, considered a trusted entity, generates and verifies authentication information, providing security keys to the femtocell to authenticate mobile units using unique challenges, thereby ensuring secure communication links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If femtocells are deployed in unsecured locations to provide distributed wireless access, then network coverage and accessibility are improved, but security and vulnerability to fraudulent activities deteriorate

Engineering Contradiction:
Improvenetwork coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a security server as an intermediary between the femtocell and the core network. This security server acts as a mediator that performs authentication and key management functions, allowing the femtocell to operate in unsecured locations while maintaining security through the intermediary's verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security-critical functions (authentication, authorization, and key management) from the femtocell itself and relocates them to a dedicated security server in the core network. This separation allows the femtocell to provide wireless access without containing sensitive security materials that could be compromised in unsecured locations.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of manufacture

If femtocells lack secure storage for secret keys to simplify deployment, then ease of installation is improved, but susceptibility to fraudulent activities worsens

Engineering Contradiction:
Improvedeployment simplicityVSAvoidfraudulent activities
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent extracts secret keys and authentication credentials from the femtocell hardware and stores them exclusively in the security server's secure storage in the core network. This extraction eliminates the need for secure physical storage in the femtocell while preventing fraudulent activities since the keys never reside in the unsecured femtocell location.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security server provides self-service authentication and key management capabilities, generating and managing security credentials autonomously without requiring secure physical infrastructure at the femtocell site. This allows simplified deployment while maintaining security through the server's own secure key management processes.

Inventive Principle:
Principle #25Self-service

3Speed

If authentication is performed using global challenges broadcast by the femtocell, then authentication speed is improved, but security reliability deteriorates due to lack of unique identification

Engineering Contradiction:
Improveauthentication speedVSAvoidauthentication reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements preliminary action by having the security server pre-generate and store unique authentication credentials for each mobile unit before authentication is needed. When a mobile unit connects, the server can quickly retrieve and verify the pre-computed credentials, achieving both fast authentication and high reliability through advance preparation of unique identification data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic authentication system where the challenge-response mechanism adapts based on the mobile unit's unique identity. The security server dynamically generates location-specific and user-specific authentication parameters, allowing the system to maintain both speed through efficient verification and reliability through unique identification of each authentication attempt.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2208375B1Method for authenticating mobile units attached to a femtocell in communication with a secure core network such as an IMS
Publication Date: 2012.03.28 ALCATEL LUCENT SA
  • EP2208375B1 patent drawingFigure 1
  • EP2208375B1 patent drawingFigure 2
  • EP2208375B1 patent drawingFigure 3

AI summary

The present invention provides a method involving a femtocell in communication with an Internet Protocol Multimedia Subsystem (IMS) network. In one embodiment, the femtocell operates according to code division multiple access (CDMA) standards. The method includes receiving, from the femtocell and at a first secure entity in the IMS network, first authentication information generated by the mobile unit using a first random number broadcast by the femtocell in a global challenge. The method also includes receiving, from a second secure entity in the secure network, at least one security key formed based on the global challenge and second authentication information for uniquely challenging the mobile unit. In one embodiment, the second secure entity is a CDMA-based authentication server. The method further includes providing the security key(s) to the femtocell in response to authenticating the mobile unit based upon the second authentication information.