Gateway Key Encryption for LoRa Operator Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The systematic transmission of all frames received by a gateway to a network server in low-power wireless communication networks leads to network traffic overload and increased processing load on the server, as existing systems lack efficient methods to filter and authenticate frames based on their origin and validity.

Innovation Solution

Implementing a method that includes asymmetric gateway key generation, where communication devices encrypt frames with a gateway public key paired with a private key stored in the gateway, and the gateway filters frames using its private key, ensuring only valid frames destined for the correct network server are transmitted, thereby reducing network and server load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If operator identification and membership checking are implemented in the radio access network, then network security and service authorization are improved, but control plane signaling load and processing overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidcontrol plane signaling load
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the operator identification and membership checking functions from the radio access network control plane and relocates them to the core network authentication domain. The RAN only handles radio resource management while the core network handles authentication, separation of security-critical functions from the access network

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the network assigns temporary frame format identifiers to operators, allowing RAN nodes to verify operator membership without direct authentication processing. This intermediary system reduces signaling load while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If frame format identification is used for operator identification, then service differentiation is improved, but processing time and computational overhead increase

Engineering Contradiction:
Improveservice differentiationVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The network performs preliminary assignment of frame format identifiers to operators before data transmission begins. Operators are pre-configured with specific frame formats, allowing RAN nodes to immediately recognize and process different operator traffic without real-time identification computations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses frame format identification as a visual marker system, where different frame formats act as distinct 'colors' or signatures that allow rapid operator identification. This marker-based approach enables quick differentiation without complex processing

Inventive Principle:
Principle #32Color changes

Data Source

PatentEP3643089B1Methods for operator identification of transmitted frames and for checking operator membership, communication device and communication gateway
Publication Date: 2022.09.28 ORANGE SA
  • EP3643089B1 patent drawingFigure 1a~1b
  • EP3643089B1 patent drawingFigure 2a~2b
  • EP3643089B1 patent drawingFigure 3~4

AI summary

The invention relates to a method for identifying the operator of transmitted frames, a method for checking operator membership, a communication device and a communication gateway. In particular, the invention relates to an identification and a frame operator membership check in the context of transmission over wireless low-energy communications networks such as LoRa (registered trademark), SigFox (registered trademark), etc. An objet of the invention is a method for identifying the operator of frames to be transmitted by a communication device belonging to an operator infrastructure over a first communications network. The method for identifying the operator comprises a first encryption, the gateway encryption, by the communication device belonging to the operator infrastructure, of a frame intended for a network server, with a public gateway key associated with the communication device in the operator infrastructure, the public gateway key being paired with a private gateway key stored in at least one gateway of the operator infrastructure. This allows reducing the load on the second communications network between the gateway and the network server, as well as the processing load on the network server.