HSS-Based MTC Application Authorization via SCEF Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing MTC communication procedures in wireless core networks do not ensure that a particular application server is authorized to connect with a specific MTC device, leading to potential unauthorized data exchange.

Innovation Solution

Storing mapping information in the wireless core network that associates authorized MTC devices with application servers, using the Service Capability Exposure Function (SCEF) to authorize communications between specific application servers and MTC devices based on subscriber profiles and access point names (APNs).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing MTC communication procedures are used, then network services can be provided between MTC devices and application servers, but unauthorized application servers can connect with MTC devices leading to security vulnerabilities

Engineering Contradiction:
Improveauthorization reliabilityVSAvoidunauthorized data exchange
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authorization by storing mapping information in the HSS before communication occurs. The HSS pre-establishes which application servers are authorized to connect with specific MTC devices, and this authorization is validated before allowing data exchange, preventing unauthorized connections from occurring in the first place

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The HSS acts as an intermediary authorization system between MTC devices and application servers. It maintains mapping information that mediates the connection process, verifying that only authorized application servers can establish connections with specific MTC devices, thus controlling the harmful factor of unauthorized data exchange

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If mapping information is stored in the wireless core network to authorize communications, then security is enhanced, but network complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidnetwork structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The HSS is leveraged for multiple functions: it continues to serve as the traditional subscriber profile storage system while also serving as the authorization system that maintains mapping information between MTC devices and application servers. This multi-functionality approach enhances security without requiring a completely separate authorization system, thereby limiting the increase in network complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10299094B2HSS-based application authorization for machine-type-communications
Publication Date: 2019.05.21 VERIZON PATENT & LICENSING INC
  • US10299094B2 patent drawing
  • US10299094B2 patent drawing
  • US10299094B2 patent drawing

AI summary

Systems described herein ensure authorized communications between application servers and machine-type communications (MTC) devices. The systems store a subscriber profile for an MTC device, the subscriber profile including application server (AS) configuration information designating application servers that are authorized to connect with the MTC device. The systems receive a non-IP data delivery (NIDD) registration request from an application server, wherein the NIDD registration request includes an identifier for the MTC device. The systems obtain, from the application server, a first identifier for the application server, and retrieve, based on the NIDD registration request, the AS configuration information from the subscriber profile. The systems determine if there is a match between the AS configuration information and the first identifier for the application server, and configure a binding of the application server and an access point name (APN) for the MTC device in response to determining that there is a match.