Group Authentication Vector for MTC Device Signaling Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing authentication methods for Machine Type Communication (MTC) devices result in network congestion due to increased signaling traffic when a large number of devices access the network simultaneously, as each device requires unique authentication vectors, which is inefficient and can be overwhelmed by a high volume of requests.

Innovation Solution

A method where MTC devices use a group authentication vector shared by the group identifier, allowing devices within the same group to authenticate using a single authentication vector, reducing the need for individual key generation and minimizing signaling traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unique authentication vectors are generated for each MTC device using individual IMSI, then authentication security is improved, but signaling traffic increases rapidly causing network congestion

Engineering Contradiction:
Improveauthentication securityVSAvoidsignaling traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the authentication process by allowing multiple MTC devices to share a common authentication vector generated from a group IMSI, rather than requiring separate authentication vectors for each device. This combining approach reduces the total number of authentication vectors needed while maintaining security through device-specific identifiers included in attach requests.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements universality by creating a single authentication vector that can serve multiple MTC devices simultaneously. The group authentication vector acts as a universal credential for all devices in the group, eliminating the need for individual unique authentication vectors and significantly reducing signaling traffic during bulk device access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If individual authentication vectors are generated for each device, then device identification precision is improved, but network processing capacity is overwhelmed by high volume requests

Engineering Contradiction:
Improvedevice identification precisionVSAvoidnetwork processing capacity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the authentication identification process into two parts: a shared group-level identifier (group IMSI) for bulk authentication and a device-specific identifier (device identifier in attach request) for individual device recognition. This segmentation allows efficient batch processing while maintaining precise device-level identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by using a common authentication vector for all devices in the group rather than generating complete individual authentication vectors for each device. This partial approach provides sufficient authentication capability for the network to verify device legitimacy without the excessive processing burden of generating unique vectors for every single device.

Inventive Principle:
Principle #16Partial or excessive action

3Quantity of substance

If group-based authentication is implemented to reduce signaling traffic, then network load is reduced, but individual device authentication capability may be compromised

Engineering Contradiction:
Improvesignaling trafficVSAvoidindividual device authentication capability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent introduces the device identifier as an intermediary element that bridges group-based authentication and individual device identification. The device identifier acts as a mediator that allows the network to authenticate devices as part of a group while still maintaining the ability to identify and manage individual devices separately, thus preserving individual authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2549785B8Method and network side entity for authenticating communication devices
Publication Date: 2016.04.06 HUAWEI TECH CO LTD

AI summary

Embodiments of the present invention disclose a method and an apparatus for authenticating a communication device, where the method includes: receiving an attach request including a group identifier and sent by an MTC device to be authenticated, where the group identifier is a group identifier of an MTC group where the MTC device to be authenticated is located; determining whether a first group authentication vector bound to the group identifier exists locally, where the first group authentication vector is an authentication vector used for authenticating MTC devices in the MTC group; and if existing, according to the first group authentication vector, authenticating the MTC device to be authenticated, and generating a system key of the MTC device to be authenticated. The technical solutions provided in the present invention can be applied to the technical field of authenticating the MTC device.