Centralized HLR Authentication for M2M Credential Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile network authentication systems for Machine to Machine (M2M) devices and consumer electronics face challenges in provisioning and changing operator-specific credentials, particularly for devices like metering devices and consumer electronics, as they require individual SIM card management or complex reprogramming, which is cumbersome and costly.
Innovation Solution
An access authentication system comprising an operator access authentication system and private access authentication systems, where the private system communicates authentication data to the operator system, allowing secure provisioning and authentication without modifying individual devices, using a private HLR/AuC that can be trusted and managed by the subscriber, facilitating easy operator changes with a single protocol for multiple devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual SIM cards are provisioned into each device for operator-specific authentication, then device authentication security is improved, but device complexity and provisioning cost increase
Solution Approach 1:
The patent extracts the authentication credential storage function from individual devices and concentrates it in a central HLR database. Instead of each device holding its own SIM card with credentials, the device identifier is stored centrally, and authentication credentials are generated and managed by the network operator's HLR system. This reduces device complexity while maintaining security through centralized control.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the HLR acts as a mediator between the device and the network. The HLR receives device identifiers, generates appropriate authentication credentials, and manages the credential distribution. This intermediary layer simplifies device provisioning while maintaining strong authentication through centralized credential management.
2Adaptability or versatility
If SIM cards are physically inserted into devices for authentication, then operator control over credentials is improved, but ease of operation deteriorates due to manual SIM replacement requirements
Solution Approach 1:
The patent replaces the mechanical SIM card insertion/removal system with an electronic/digital credential management system. Instead of physically swapping SIM cards, operators can remotely provision, update, and manage authentication credentials through the HLR database using electronic communication protocols. This eliminates the need for physical SIM handling while maintaining operator control over credential distribution.
3Reliability
If credentials are provisioned into both AuC and device, then authentication reliability is improved, but loss of time increases due to dual provisioning requirements
Solution Approach 1:
The patent extracts the credential storage function from the device side and consolidates it in the HLR. Instead of provisioning credentials to both the AuC and the device separately, the system stores device identifiers centrally in the HLR and generates credentials on-demand during authentication. This eliminates redundant credential provisioning while maintaining authentication reliability through centralized verification.
4Measurement precision
If individual device registration is required for each operator, then authentication precision is improved, but productivity deteriorates due to manual registration processes
Solution Approach 1:
The patent enables self-service provisioning where devices can automatically register with operators using standardized protocols. The device sends its identifier to the HLR, which automatically generates and returns the appropriate authentication credentials without requiring manual intervention. This maintains precise device identification through the HLR's centralized database while dramatically improving provisioning speed through automated credential generation and distribution.
Data Source
AI summary
An access authentication system for authenticating a subscriber of a service, the access authentication system comprising an operator access authentication system and one or more private access authentication systems, each private access authentication system being communicatively connectable with the operator access authentication system, the operator access authentication system being adapted to provide one or more authentication functions for facilitating authentication of subscribers of the service based on respective subscriber authentication data items associated with credentials of the subscriber; wherein each private access authentication system is adapted to communicate one or more subscriber authentication data items to said operator access authentication system; and wherein each private access authentication system is further adapted to communicate one or more verification data items indicative of the private access authentication system operating in at least one predetermined state.


