Hub Device Authentication for M2M Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for authenticating large numbers of devices to wireless telecommunications networks are inefficient, particularly for machine-to-machine (M2M) applications, as they require separate SIM cards and provisioning, leading to high costs and operational disruptions due to the low and sporadic use of these devices, and alternative solutions like soft SIMs pose security issues or necessitate network redesign.

Innovation Solution

A system where multiple devices share a single SIM (U)SIM, connected to a hub device, which provides authentication information including temporary identifiers and key associations, allowing parallel access to wireless access networks, with modifications to the core network to track and manage these devices efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each device is provisioned with a separate SIM card, then authentication capability is provided, but provisioning costs and operational disruptions increase due to low and sporadic device usage

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple machine devices share a single SIM card inserted in a hub device, consolidating authentication capabilities. Instead of each device having its own SIM, the hub device's SIM serves all connected devices, eliminating individual provisioning requirements and reducing operational complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hub device's SIM card serves multiple functions by providing authentication for multiple different machine devices. The single SIM card becomes a universal authentication credential that can be shared across various devices connected to the hub, rather than being device-specific.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If a soft SIM is used instead of physical SIM cards, then provisioning costs are reduced, but security issues arise

Engineering Contradiction:
Improveprovisioning complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The hub device acts as an intermediary between the machine devices and the network. It holds the physical SIM card and security credentials, and mediates authentication by providing authentication information to connected devices. This separates security management from individual devices while maintaining strong security through the physical SIM.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If authentication information is stored in the hub device, then individual device provisioning is eliminated, but the hub device becomes a single point of failure

Engineering Contradiction:
Improveprovisioning complexityVSAvoidsystem reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Authentication information is segmented into multiple components (temporary identifiers, key associations) that are distributed to multiple devices. When a device connects to the hub, it receives specific authentication credentials that are valid for that device's connection, spreading the authentication burden and eliminating the single point of failure.

Inventive Principle:
Principle #1Segmentation

4Reliability

If machine devices authenticate individually through the core network, then security is maintained, but network resources are heavily consumed

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Authentication information is prepared in advance and stored in the hub device's SIM card. When devices need to authenticate, they receive pre-configured credentials from the hub, eliminating the need for real-time authentication transactions with the core network for each device. The preliminary authentication setup reduces ongoing network resource consumption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9271148B2Authentication in a wireless telecommunications network
Publication Date: 2016.02.23 VODAFONE IP LICENSING LTD
  • US9271148B2 patent drawing
  • US9271148B2 patent drawing
  • US9271148B2 patent drawing

AI summary

To facilitate authentication over a wireless access network, it is proposed to provide a hub device having an authentication storage means (i.e. a (U)SIM) to which one or more machine devices are connected. Each machine devices connects to a wireless access network and in order to authenticate with that network requests authentication information from the hub device. The core network of the wireless access network, authenticates each machine device and provides the machine devices with parallel access to the access network in accordance with authentication information obtained from the hub device. The authentication information is unique to the respective machine device but also associated with information stored on the authentication storage means of the hub device.