FIDO Authentication for Non-SIM Devices via Wi-Fi

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for non-SIM devices to access 3GPP networks via Wi-Fi face challenges such as performance bottlenecks and reduced user experience due to reliance on certificate-based authentication and username/password methods, which are cumbersome and insecure.

Innovation Solution

Implementing FIDO Alliance specifications, specifically UAF and U2F protocols, to enable biometric authentication and secure access for non-SIM devices by registering them with a FIDO server and authenticating through an AAA server using EAP-TLS extended with FIDO authentication data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based authentication is used for non-SIM devices to access 3GPP networks via Wi-Fi, then network security is maintained, but performance bottlenecks occur and user experience deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the authentication parameter from traditional certificate-based EAP-TLS to FIDO-based authentication. This parameter change enables biometric authentication methods (fingerprint, facial recognition) that are more user-friendly while maintaining security. The FIDO authentication flow with local credential verification reduces network round-trips and processing overhead, thereby improving access performance and eliminating bottlenecks.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent substitutes the mechanical certificate verification process with a biometric-based FIDO authentication mechanism. Instead of relying on digital certificate exchanges and cryptographic handshakes that create performance bottlenecks, the system uses biometric sensors and local secure enclave verification, which are faster and more efficient while maintaining or enhancing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Device complexity

If username/password authentication is used for non-SIM devices, then device complexity is reduced, but security is compromised and user experience becomes cumbersome

Engineering Contradiction:
Improveauthentication complexityVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces FIDO credentials as an intermediary between the simple username/password interface and the secure authentication backend. The FIDO credential object, stored in the device's secure enclave, acts as a mediator that provides strong cryptographic authentication without requiring users to manage complex certificates or remember passwords. This intermediary layer maintains security while simplifying the user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses FIDO credentials as a secure copy or representation of user identity that replaces both username/password and certificate-based authentication. The credential object contains cryptographic material that proves user identity without exposing passwords or requiring certificate management, thereby achieving both simplicity and security.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If traditional authentication methods are used, then compatibility with existing systems is maintained, but adaptability to modern security standards is reduced

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements FIDO authentication that serves multiple functions: it works for both SIM and non-SIM devices, supports multiple authentication factors (biometric, PIN, password), and is compatible with both 3GPP and non-3GPP networks. The FIDO credential can be used across different services and networks, providing universal authentication that adapts to various security requirements without requiring separate solutions for each case.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10856135B2Method and apparatus for network access
Publication Date: 2020.12.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10856135B2 patent drawing
  • US10856135B2 patent drawing
  • US10856135B2 patent drawing

AI summary

A method at a Fast Identity Online, FIDO, server for facilitating a terminal device without a Subscriber Identity Module, SIM, card to access a first network via a second network. Association information for the terminal device without a SIM card is obtained indicative of an association between the terminal device without a SIM card and a user subscription account and authentication information for the terminal device without a SIM card and causes the terminal device without a SIM card to be registered with the FIDO server according to a set of FIDO Alliance specifications based at least on the association information and the authentication information. Registration information for the terminal device without a SIM card is provided to an Authentication, Authorization, and Accounting, AAA, server, in response to receipt at the AAA server of an authentication request from the terminal device without a SIM card.