Femtocell Access Control Using Temporary Identities for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control methods in wireless networks, particularly for femtocells and WLANs, face challenges in protecting user identity privacy and managing access control efficiently, especially for non-technical operators, and fail to provide secure and seamless access while allowing emergency calls in closed user groups.

Innovation Solution

Implementing a femtocell system that uses temporary identities for authentication and stores permanent identities internally, allowing operators to manage access through owner-assigned IDs without exposing sensitive information over the air interface, and enabling operating modes for open, closed, or query-based access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If permanent identities are transmitted over the air interface for authentication, then network access control can be implemented, but user identity privacy is compromised

Engineering Contradiction:
Improvenetwork access controlVSAvoiduser identity privacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a temporary identity (TMSI) as an intermediary between the user's permanent identity (IMSI) and the network. The TMSI is transmitted over the air interface instead of the permanent identity, serving as a mediator that enables authentication while protecting the user's true identity from exposure during wireless transmission

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the user's identity information in the form of a temporary identity (TMSI). This temporary copy is used for authentication purposes over the air interface, while the original permanent identity (IMSI) remains protected and stored only in secure locations (USIM card and network databases), preventing exposure of the true identity

Inventive Principle:
Principle #26Copying

2Reliability

If femtocells use traditional access control methods, then network security can be maintained, but non-technical operators struggle to manage access efficiently

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess management for operators
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables femtocell operators to independently manage access control by allowing them to configure the femtocell with their own lists of authorized user identities. The system provides self-service capabilities where operators can add, remove, and manage authorized users without requiring intervention from the mobile network operator, simplifying operation for non-technical users

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary action by pre-configuring the femtocell with access control lists and authentication parameters before deployment. The operator sets up the authorized user lists in advance, and the femtocell automatically enforces these access control policies, eliminating the need for complex real-time management decisions

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If closed user groups are implemented in femtocells, then user privacy is protected, but emergency calls cannot be made by unauthorized users

Engineering Contradiction:
Improveuser identity privacy protectionVSAvoidemergency call capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary anti-action by pre-configuring the femtocell to automatically allow emergency calls from any user, even those not in the authorized closed user group. This preemptive measure ensures that emergency communication capabilities are preserved while maintaining privacy protection for normal operations, counteracting the potential harmful effect of blocking emergency calls

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10206102B2Network access control methods and apparatus
Publication Date: 2019.02.12 APPLE INC
  • US10206102B2 patent drawing
  • US10206102B2 patent drawing
  • US10206102B2 patent drawing

AI summary

Methods and apparatus that provide user access control within wireless networks such as those having both fixed and portable nodes. In one embodiment, the network comprises a 3G cellular network or Interworking WLAN (iWLAN), and the portable nodes comprise Home Node B (HNB) base stations. The HNB is configured to authenticate new users, and provide network access while still maintaining user privacy. The portable nodes also may operate in a number of different operating modes which provide different functional control over user access. In one variant, an easy-to-use owner-assigned ID based access control mechanism with a reliable unambiguous user ID is utilized. Methods for providing access control across differing network architectures and protocols, such the aforementioned iWLAN, and business methods, are also described.