H-MVNO Device Mobility via Proxy Authentication Across Partner Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for supporting device mobility in virtual mobile network operators (MVNOs) face challenges such as limited coverage areas, the need for dual SIM capability in devices, and security concerns over credential sharing, which hinder seamless access to partner Mobile Network Operators (MNOs) and application servers.
Innovation Solution
A method where a customer device, subscribed to a Home-Mobile Virtual Network Operator (H-MVNO), can automatically connect to a partner MNO network using a proxy authentication mechanism, where the visiting network's HSS or AUSF/UDM acts as a proxy, allowing access to the H-MVNO application server without manual user intervention, and maintains connectivity and QoS settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If MVNO shares subscriber credentials and authentication information with partner MNO, then coverage area is extended, but security control is weakened and information must be continuously updated
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where the MVNO's authentication server acts as a mediator between the subscriber and the MNO network. Instead of sharing credentials directly, the MVNO server receives authentication requests from the MNO, verifies them against its subscriber database, and returns authentication decisions. This mediator approach extends coverage to partner networks while maintaining security control and avoiding the need for continuous credential updates.
2Adaptability or versatility
If dual SIM capability is implemented in customer devices, then access to multiple networks is enabled, but device complexity increases and legacy devices are incompatible
Solution Approach 1:
The patent uses the network side (MVNO authentication server) as an intermediary to provide multi-network access without requiring dual SIM hardware. The subscriber device maintains a single SIM with MVNO credentials, and when accessing partner MNO networks, the authentication request is routed through the MVNO's server which mediates the authentication process. This approach enables network access versatility while keeping device complexity low and compatible with legacy single SIM devices.
3Ease of operation
If automatic connection to partner MNO is implemented, then user convenience is improved, but authentication and authorization complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-configuring the MVNO's authentication server with the subscriber's credentials and authorization policies before the subscriber needs to access a partner network. When the subscriber device automatically connects to a partner MNO, the authentication request is already validated against pre-stored credentials, and authorization decisions are made based on pre-configured policies. This preliminary preparation enables automatic connection convenience while managing authentication complexity on the network side rather than the device side.
Data Source
AI summary
A customer communications device of a first network operator (H-MVNO) detects a network identifier from an access point of a second network (MNO) indicating that the second network provides access for first network devices in accordance with a sharing agreement. The device registers via the access point of the second network. Authentication and authorization for the device is performed by a first network security entity on behalf second network, with the device using a restricted use first IP address acquired from a DHCP in the second network. The home network (H-MVNO) sets up the session QoS from the home PCF and home SMF toward the visiting network SMF. The visiting network SMF executes the traffic QoS class via the visiting UPF with the device using a second IP address acquired from a DHCP in the second network for user plane data traffic through the second network.


