HSS-Based MTC Application Authorization via SCEF Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing MTC communication procedures in wireless core networks do not ensure that a particular application server is authorized to connect with a specific MTC device, leading to potential unauthorized data exchange.
Innovation Solution
Storing mapping information in the wireless core network that associates authorized MTC devices with application servers, using the Service Capability Exposure Function (SCEF) to authorize communications between specific application servers and MTC devices based on subscriber profiles and access point names (APNs).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing MTC communication procedures are used, then network services can be provided between MTC devices and application servers, but unauthorized application servers can connect with MTC devices leading to security vulnerabilities
Solution Approach 1:
The system performs preliminary authorization by storing mapping information in the HSS before communication occurs. The HSS pre-establishes which application servers are authorized to connect with specific MTC devices, and this authorization is validated before allowing data exchange, preventing unauthorized connections from occurring in the first place
Solution Approach 2:
The HSS acts as an intermediary authorization system between MTC devices and application servers. It maintains mapping information that mediates the connection process, verifying that only authorized application servers can establish connections with specific MTC devices, thus controlling the harmful factor of unauthorized data exchange
2Reliability
If mapping information is stored in the wireless core network to authorize communications, then security is enhanced, but network complexity increases
Solution Approach 1:
The HSS is leveraged for multiple functions: it continues to serve as the traditional subscriber profile storage system while also serving as the authorization system that maintains mapping information between MTC devices and application servers. This multi-functionality approach enhances security without requiring a completely separate authorization system, thereby limiting the increase in network complexity
Data Source
AI summary
Systems described herein ensure authorized communications between application servers and machine-type communications (MTC) devices. The systems store a subscriber profile for an MTC device, the subscriber profile including application server (AS) configuration information designating application servers that are authorized to connect with the MTC device. The systems receive a non-IP data delivery (NIDD) registration request from an application server, wherein the NIDD registration request includes an identifier for the MTC device. The systems obtain, from the application server, a first identifier for the application server, and retrieve, based on the NIDD registration request, the AS configuration information from the subscriber profile. The systems determine if there is a match between the AS configuration information and the first identifier for the application server, and configure a binding of the application server and an access point name (APN) for the MTC device in response to determining that there is a match.


