Hub Device Authentication for M2M Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for authenticating large numbers of devices to wireless telecommunications networks are inefficient, particularly for machine-to-machine (M2M) applications, as they require separate SIM cards and provisioning, leading to high costs and operational disruptions due to the low and sporadic use of these devices, and alternative solutions like soft SIMs pose security issues or necessitate network redesign.
Innovation Solution
A system where multiple devices share a single SIM (U)SIM, connected to a hub device, which provides authentication information including temporary identifiers and key associations, allowing parallel access to wireless access networks, with modifications to the core network to track and manage these devices efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each device is provisioned with a separate SIM card, then authentication capability is provided, but provisioning costs and operational disruptions increase due to low and sporadic device usage
Solution Approach 1:
Multiple machine devices share a single SIM card inserted in a hub device, consolidating authentication capabilities. Instead of each device having its own SIM, the hub device's SIM serves all connected devices, eliminating individual provisioning requirements and reducing operational complexity.
Solution Approach 2:
The hub device's SIM card serves multiple functions by providing authentication for multiple different machine devices. The single SIM card becomes a universal authentication credential that can be shared across various devices connected to the hub, rather than being device-specific.
2Device complexity
If a soft SIM is used instead of physical SIM cards, then provisioning costs are reduced, but security issues arise
Solution Approach 1:
The hub device acts as an intermediary between the machine devices and the network. It holds the physical SIM card and security credentials, and mediates authentication by providing authentication information to connected devices. This separates security management from individual devices while maintaining strong security through the physical SIM.
3Device complexity
If authentication information is stored in the hub device, then individual device provisioning is eliminated, but the hub device becomes a single point of failure
Solution Approach 1:
Authentication information is segmented into multiple components (temporary identifiers, key associations) that are distributed to multiple devices. When a device connects to the hub, it receives specific authentication credentials that are valid for that device's connection, spreading the authentication burden and eliminating the single point of failure.
4Reliability
If machine devices authenticate individually through the core network, then security is maintained, but network resources are heavily consumed
Solution Approach 1:
Authentication information is prepared in advance and stored in the hub device's SIM card. When devices need to authenticate, they receive pre-configured credentials from the hub, eliminating the need for real-time authentication transactions with the core network for each device. The preliminary authentication setup reduces ongoing network resource consumption.
Data Source
AI summary
To facilitate authentication over a wireless access network, it is proposed to provide a hub device having an authentication storage means (i.e. a (U)SIM) to which one or more machine devices are connected. Each machine devices connects to a wireless access network and in order to authenticate with that network requests authentication information from the hub device. The core network of the wireless access network, authenticates each machine device and provides the machine devices with parallel access to the access network in accordance with authentication information obtained from the hub device. The authentication information is unique to the respective machine device but also associated with information stored on the authentication storage means of the hub device.


