H-MVNO Device Mobility via Proxy Authentication Across Partner Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for supporting device mobility in virtual mobile network operators (MVNOs) face challenges such as limited coverage areas, the need for dual SIM capability in devices, and security concerns over credential sharing, which hinder seamless access to partner Mobile Network Operators (MNOs) and application servers.

Innovation Solution

A method where a customer device, subscribed to a Home-Mobile Virtual Network Operator (H-MVNO), can automatically connect to a partner MNO network using a proxy authentication mechanism, where the visiting network's HSS or AUSF/UDM acts as a proxy, allowing access to the H-MVNO application server without manual user intervention, and maintains connectivity and QoS settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If MVNO shares subscriber credentials and authentication information with partner MNO, then coverage area is extended, but security control is weakened and information must be continuously updated

Engineering Contradiction:
Improvecoverage areaVSAvoidsecurity control
Core Design Contradiction:
Area of stationary objectVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where the MVNO's authentication server acts as a mediator between the subscriber and the MNO network. Instead of sharing credentials directly, the MVNO server receives authentication requests from the MNO, verifies them against its subscriber database, and returns authentication decisions. This mediator approach extends coverage to partner networks while maintaining security control and avoiding the need for continuous credential updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If dual SIM capability is implemented in customer devices, then access to multiple networks is enabled, but device complexity increases and legacy devices are incompatible

Engineering Contradiction:
Improvenetwork access capabilityVSAvoiddual SIM capability
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses the network side (MVNO authentication server) as an intermediary to provide multi-network access without requiring dual SIM hardware. The subscriber device maintains a single SIM with MVNO credentials, and when accessing partner MNO networks, the authentication request is routed through the MVNO's server which mediates the authentication process. This approach enables network access versatility while keeping device complexity low and compatible with legacy single SIM devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automatic connection to partner MNO is implemented, then user convenience is improved, but authentication and authorization complexity increases

Engineering Contradiction:
Improveautomatic connectionVSAvoidauthentication complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring the MVNO's authentication server with the subscriber's credentials and authorization policies before the subscriber needs to access a partner network. When the subscriber device automatically connects to a partner MNO, the authentication request is already validated against pre-stored credentials, and authorization decisions are made based on pre-configured policies. This preliminary preparation enables automatic connection convenience while managing authentication complexity on the network side rather than the device side.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12408030B2Methods and apparatus for supporting device mobility allowing a service subscriber to receive service in multiple networks
Publication Date: 2025.09.02 CHARTER COMM OPERATING LLC
  • US12408030B2 patent drawing
  • US12408030B2 patent drawing
  • US12408030B2 patent drawing

AI summary

A customer communications device of a first network operator (H-MVNO) detects a network identifier from an access point of a second network (MNO) indicating that the second network provides access for first network devices in accordance with a sharing agreement. The device registers via the access point of the second network. Authentication and authorization for the device is performed by a first network security entity on behalf second network, with the device using a restricted use first IP address acquired from a DHCP in the second network. The home network (H-MVNO) sets up the session QoS from the home PCF and home SMF toward the visiting network SMF. The visiting network SMF executes the traffic QoS class via the visiting UPF with the device using a second IP address acquired from a DHCP in the second network for user plane data traffic through the second network.