Femtocell Authentication via IMS Intermediary Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Femtocells, lacking secure storage for secret keys, are vulnerable to fraudulent representation and hacking, making it difficult for networks to verify the authenticity of authentication information and random numbers, especially since they are deployed in unsecured locations.

Innovation Solution

Implementing a method where a femtocell communicates with a secure core network, such as an IMS network, to receive and verify a legitimate random number, using a global challenge mechanism where the mobile unit computes an authentication response based on a key known only to the mobile unit and not the femtocell, ensuring the authenticity of the authentication information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If femtocells are deployed in unsecured locations to reduce deployment cost and increase accessibility, then ease of manufacture and adaptability improve, but security and reliability deteriorate

Engineering Contradiction:
Improvedeployment costVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces a secure core network entity as an intermediary between the unsecured femtocell and the authentication system. This mediator verifies the authenticity of random numbers and authentication information, allowing the femtocell to operate in unsecured locations while maintaining security through the intermediary's verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If femtocells lack secure storage for secret keys to reduce device complexity and cost, then device complexity decreases, but vulnerability to fraudulent representation increases

Engineering Contradiction:
Improvesecure storage requirementsVSAvoidfraudulent representation
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The secure core network entity acts as a mediator that compensates for the femtocell's lack of secure storage. By verifying authentication information and random numbers through this intermediary, the system maintains security without requiring secure storage in the femtocell itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the physical secure storage mechanism with a network-based verification mechanism. Instead of storing secret keys locally in secure hardware, the femtocell uses network-based authentication verification through the secure core network entity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If base stations periodically change RAND values to prevent replay attacks, then security improves, but the complexity of verifying authenticity in unsecured femtocells increases

Engineering Contradiction:
ImprovesecurityVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure core network entity serves as an intermediary that handles the complex verification of periodically changing RAND values. This mediator absorbs the verification complexity, allowing femtocells to implement frequent RAND changes for security without bearing the full burden of verification complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8230035B2Method for authenticating mobile units attached to a femtocell that operates according to code division multiple access
Publication Date: 2012.07.24 ALCATEL LUCENT SA
  • US8230035B2 patent drawing
  • US8230035B2 patent drawing
  • US8230035B2 patent drawing

AI summary

The present invention provides a method involving a femtocell in communication with a secure core network such as an Internet Protocol Multimedia Subsystem (IMS) network. The method includes receiving, from the femtocell and at a first secure entity in the IMS network, a global challenge including information indicating a random number. The method also includes receiving an authentication response computed by a mobile unit based on the random number and the first key known by the mobile unit and not known by the femtocell. The method further includes determining, at the first secure entity, that the random number is a legitimate random number provided to the femtocell by the IMS network.