Group Authentication for Machine-Type Communication Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face inefficiencies in authenticating a large number of Machine-type Communication (MTC) Devices, as individual authentication generates excessive signaling and wastes bandwidth, and the limited range of subscriber identities may be exhausted, especially considering low-power devices that aim to conserve battery life.

Innovation Solution

Implementing a method where MTC Devices within a group share a subscription and authentication information, using a combination of group authentication information and device-specific authentication information, with the network generating a group authentication challenge and the device responding to it, while also deriving device-specific session keys for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual authentication is performed for each MTC Device using unique subscriber identity (IMSI), then device authentication reliability is improved, but signaling load and network bandwidth consumption increase excessively

Engineering Contradiction:
Improvedevice authentication reliabilityVSAvoidsignaling load
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Multiple MTC Devices are merged into a group that shares a common group identifier (GI) and group authentication information. Instead of each device having a separate IMSI, devices in the same group use the shared group identifier for authentication, thereby reducing the number of authentication vectors and signaling messages required while maintaining authentication reliability through device-specific authentication elements within the group framework.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If each MTC Device is associated with a unique subscriber identity (IMSI), then individual device identification is improved, but the range of subscriber identities is exhausted rapidly

Engineering Contradiction:
Improveindividual device identificationVSAvoidsubscriber identity range
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The subscriber identity structure is segmented into a group identifier (GI) that is shared by multiple devices and a device-specific identifier element that provides individual device identification. This segmentation allows many devices to be grouped under a single GI, conserving the limited subscriber identity range while maintaining the ability to identify and authenticate individual devices through their specific identifier elements within the group.

Inventive Principle:
Principle #1Segmentation

3Reliability

If individual authentication procedures are implemented for each MTC Device, then authentication security is improved, but power consumption of low-power devices increases

Engineering Contradiction:
Improveauthentication securityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Authentication procedures are merged at the group level where multiple devices share common authentication information and can be authenticated together using a single authentication vector set. This reduces the number of individual authentication transactions required, thereby reducing the signaling overhead and power consumption for low-power MTC devices while maintaining security through device-specific authentication elements.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If group authentication is implemented to reduce signaling load, then network resource efficiency is improved, but individual device identity assurance may be compromised

Engineering Contradiction:
Improvenetwork resource efficiencyVSAvoidindividual device identity assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The authentication system implements local quality by having different authentication information at different levels: group-level authentication information (shared GI and group authentication data) for efficient group authentication, and device-specific authentication elements (unique device identifiers, device-specific keys) for individual device identity assurance. This layered approach allows the system to benefit from group authentication efficiency while maintaining the ability to identify and authenticate individual devices when required.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2666316B1Method and apparatus for authenticating a communication device
Publication Date: 2020.06.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2666316B1 patent drawingFigure 1~2
  • EP2666316B1 patent drawingFigure 3~4
  • EP2666316B1 patent drawingFigure 5

AI summary

According to an aspect of the present invention there is provided a method of operating a communication device, the communication device being part of a group comprising two or more communication devices that share a subscription to a communication network. The method comprises receiving a group authentication challenge from the network, at least part of the group authentication challenge having been generated using group authentication information that is associated with the shared subscription. The device then generates a device specific response to the group authentication challenge using the group authentication information and device specific authentication information and sends the device specific response to the network. The device is for example a member of a machine-type communication device group.