IMEI Interrogation for Mobile Network Device Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures in mobile communication networks, particularly when using WiFi access, fail to adequately authenticate and authorize mobile devices, leading to potential unauthorized access and inability to monitor or deny device usage effectively.
Innovation Solution
The method involves interrogating the International Mobile Equipment Identity (IMEI) of mobile devices during connection setup via a wireless radio access network, providing this information to the mobile packet core network, which allows for monitoring and authorization, enabling lawful interception and ensuring legitimate device usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If authentication methods such as EAP-SIM/AKA, WPA2 and IPsec tunnels are used for WiFi access to mobile packet core network, then user identification capability is improved, but device authorization monitoring capability remains insufficient
Solution Approach 1:
The patent segments the identification process into two distinct parts: user identification (handled by existing EAP-SIM/AKA authentication) and device identification (handled by the new IMEI interrogation mechanism). This segmentation allows each component to specialize in its function, with the authentication server now capable of both verifying user credentials and capturing device identity information through the identity request mechanism.
Solution Approach 2:
The authentication server acts as an intermediary between the mobile device and the network, mediating the identity request process. It receives the identity request from the device, extracts the IMEI information, and forwards it to the appropriate network entities for authorization decisions. This intermediary role enables centralized control over device authorization monitoring without requiring direct communication between devices and authorization systems.
2Ease of operation
If only user identification methods are used in WiFi access networks, then authentication process is simplified, but security against unauthorized devices is compromised
Solution Approach 1:
The patent implements preliminary action by interrogating the device identity (IMEI) during the initial authentication phase, before the device is fully authorized for network access. The authentication server requests and captures the identity information as part of the EAP-SIM/AKA authentication process, ensuring that device authorization checks can be performed in advance, preventing unauthorized devices from accessing the network.
Solution Approach 2:
The system implements feedback by using the captured device identity information to influence subsequent authorization decisions. The authentication server receives the identity request, extracts the IMEI, and provides this information back to the network for authorization verification. This feedback loop ensures that the network can make informed decisions about whether to grant access based on both user credentials and device identity.
3Measurement precision
If device identification information is collected during connection setup, then real-time monitoring capability is improved, but network protocol complexity increases
Solution Approach 1:
The patent applies universality by making the authentication server multi-functional: it continues to perform its traditional authentication function while simultaneously capturing device identity information through the identity request mechanism. This existing authentication infrastructure is thus enhanced with additional monitoring capability without requiring separate dedicated systems, reducing overall network complexity.
Solution Approach 2:
The mobile device itself provides the device identification information (IMEI) in response to the authentication server's identity request during the authentication process. The device's own identity mechanism serves the dual purpose of self-identification and network monitoring, eliminating the need for separate device registration systems and simplifying the overall protocol architecture.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a method of improving security in a communication network comprising a mobile device, a core network, a mobile packet core network and a wireless radio access network for access of the mobile device to the core network via the mobile packet core network. The method is characterized in that an identification of the mobile device (IMEI) is determined during connection setup of the mobile device (UE) via the wireless radio access network to the mobile packet core network. Furthermore an authentication entity of a mobile packet core network of a communication network is described.