IoT Device Network Authentication via Companion UE
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies cannot satisfy the requirement of remotely obtaining an operator credential for Internet of Things (IoT) devices that do not have a pre-issued credential, making it difficult for them to access a cellular network.
Innovation Solution
A terminal device without a pre-issued credential can obtain a shared key for network authentication by using a companion device that holds a credential, through a Diffie-Hellman key exchange process, allowing it to access the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If IoT devices are delivered without pre-configured credentials to reduce costs and simplify deployment, then operational costs and deployment complexity are reduced, but the ability to remotely download operator credentials is lost
Solution Approach 1:
The patent introduces a companion UE as an intermediary device that bridges the IoT device and the network. The companion UE holds the credential and assists the IoT device in obtaining authentication credentials through key exchange protocols, enabling the IoT device to access the network without having a pre-configured credential
2Reliability
If conventional SIM cards are used in IoT devices to ensure security and stability, then authentication security is improved, but device complexity and deployment difficulty increase
Solution Approach 1:
The patent extracts the credential storage function from the IoT device itself and places it in the companion UE. The IoT device only needs to store temporary authentication credentials obtained through key exchange, while the permanent credential remains in the companion UE, significantly reducing the IoT device's complexity
Solution Approach 2:
The companion UE acts as an intermediary that handles credential management and authentication operations, allowing the IoT device to benefit from secure authentication without incorporating a complex SIM card or credential management system
3Adaptability or versatility
If eSIM with remote credential configuration is used to enable flexible network access, then adaptability is improved, but the requirement for initial credential configuration increases device complexity
Solution Approach 1:
The companion UE serves as an intermediary that enables remote credential configuration for the IoT device without requiring the IoT device itself to have initial credentials. The companion UE uses its own credential to facilitate the credential download process to the IoT device
Solution Approach 2:
The system enables self-service credential provisioning where the IoT device can autonomously obtain credentials through the companion UE without manual configuration or pre-provisioning, making the credential acquisition process automatic and simplifying deployment
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables IoT devices to access a cellular network by establishing a secure authentication channel without requiring a pre-configured credential, simplifying the initial network attachment process and reducing operational costs.
Implementation Method 1
a terminal device not having a credential pre-issued by an operator may obtain, from the server in a DH key exchange manner by using another terminal device holding a credential, a shared key used for authentication with an operator network
Data Source
Figure 1~2
Figure 3~4
Figure 5~7
AI summary
This application discloses a mobile network authentication method, a terminal device, a server, and a network authentication entity. The method includes: receiving, by a first terminal device, a DH public key and a first ID that are sent by at least one second terminal device; sending, by the first terminal device, a first message to a server, where the first message includes a DH public key of each second terminal device of the at least one second terminal device and a first ID of the second terminal device; receiving, by the first terminal device, a second message sent by the server, where the second message includes a DH public key of the server and a second ID of the second terminal device that is generated by the server; and sending, by the first terminal device, the second ID of the second terminal device and the DH public key of the server to the second terminal device. In this way, even if a terminal device does not have a credential pre-issued by an operator network, the terminal device can still obtain a credential of the operator network.