Group Authentication for Machine-Type Communication Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication networks face inefficiencies in authenticating a large number of Machine-type Communication (MTC) Devices, as individual authentication generates excessive signaling and wastes bandwidth, and the limited range of subscriber identities may be exhausted, especially considering low-power devices that aim to conserve battery life.
Innovation Solution
Implementing a method where MTC Devices within a group share a subscription and authentication information, using a combination of group authentication information and device-specific authentication information, with the network generating a group authentication challenge and the device responding to it, while also deriving device-specific session keys for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual authentication is performed for each MTC Device using unique subscriber identity (IMSI), then device authentication reliability is improved, but signaling load and network bandwidth consumption increase excessively
Solution Approach 1:
Multiple MTC Devices are merged into a group that shares a common group identifier (GI) and group authentication information. Instead of each device having a separate IMSI, devices in the same group use the shared group identifier for authentication, thereby reducing the number of authentication vectors and signaling messages required while maintaining authentication reliability through device-specific authentication elements within the group framework.
2Adaptability or versatility
If each MTC Device is associated with a unique subscriber identity (IMSI), then individual device identification is improved, but the range of subscriber identities is exhausted rapidly
Solution Approach 1:
The subscriber identity structure is segmented into a group identifier (GI) that is shared by multiple devices and a device-specific identifier element that provides individual device identification. This segmentation allows many devices to be grouped under a single GI, conserving the limited subscriber identity range while maintaining the ability to identify and authenticate individual devices through their specific identifier elements within the group.
3Reliability
If individual authentication procedures are implemented for each MTC Device, then authentication security is improved, but power consumption of low-power devices increases
Solution Approach 1:
Authentication procedures are merged at the group level where multiple devices share common authentication information and can be authenticated together using a single authentication vector set. This reduces the number of individual authentication transactions required, thereby reducing the signaling overhead and power consumption for low-power MTC devices while maintaining security through device-specific authentication elements.
4Productivity
If group authentication is implemented to reduce signaling load, then network resource efficiency is improved, but individual device identity assurance may be compromised
Solution Approach 1:
The authentication system implements local quality by having different authentication information at different levels: group-level authentication information (shared GI and group authentication data) for efficient group authentication, and device-specific authentication elements (unique device identifiers, device-specific keys) for individual device identity assurance. This layered approach allows the system to benefit from group authentication efficiency while maintaining the ability to identify and authenticate individual devices when required.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
According to an aspect of the present invention there is provided a method of operating a communication device, the communication device being part of a group comprising two or more communication devices that share a subscription to a communication network. The method comprises receiving a group authentication challenge from the network, at least part of the group authentication challenge having been generated using group authentication information that is associated with the shared subscription. The device then generates a device specific response to the group authentication challenge using the group authentication information and device specific authentication information and sends the device specific response to the network. The device is for example a member of a machine-type communication device group.