IP Address and ICCID Association for Mobile Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access control methods for mobile communication devices face challenges in managing network security across different communication networks or security domains, particularly due to dynamic IP address assignments and the complexity of security administration, which leads to increased administrative burdens and unnecessary transport overhead when confidentiality and integrity protection are not required.
Innovation Solution
A system and method utilizing a Mobility Management Entity (MME), Packet Data Network Gateway (PDN-GW), and Home Subscriber Server (HSS) to provide a secure association between a User Equipment's (UE) IP address and its Integrated Circuit Card Identifier (ICCID) across security domains, eliminating the need for overlay security mechanisms like VPNs when no confidentiality and integrity protection is needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP address-based access control is used, then network security control is implemented, but administrative complexity increases due to dynamic IP address assignments
Solution Approach 1:
The patent introduces an intermediary mapping system that associates dynamic IP addresses with static device identifiers (MAC addresses, IMEI, ICCID). This intermediary layer allows security policies to be defined based on device identity rather than transient IP addresses, eliminating the need for manual IP address mapping and policy updates when IP addresses change.
Solution Approach 2:
The patent creates a virtual mapping table that copies and stores the relationship between IP addresses and device identifiers in the network infrastructure (e.g., in the MME or gateway). This copied information allows security devices to enforce policies based on device identity without needing real-time knowledge of current IP address assignments, simplifying administration.
2Reliability
If VPN techniques are applied for security, then authentication and security control are improved, but transport overhead and complexity increase
Solution Approach 1:
The patent extracts the authentication and identification function from the VPN overlay mechanism and implements it natively at the IP layer using standard IP address assignment and filtering. By taking out the VPN-specific authentication layer and using core network authentication (HSS/AAA) combined with IP address binding to device identifiers, the solution achieves security control without VPN transport overhead.
Solution Approach 2:
The patent uses standard, widely-deployed network infrastructure components (MME, HSS, gateway) that already perform authentication and IP address management, rather than deploying expensive VPN infrastructure. The solution leverages existing short-lived IP address assignments combined with device identifier binding, avoiding the need for persistent VPN tunnels and associated overhead.
3Ease of operation
If domain-based security policies are implemented, then traffic identification based on SGT is improved, but proprietary support is required on all network nodes
Solution Approach 1:
The patent makes the security identification mechanism universal by using standard IP address assignment and filtering capabilities that are already present in all modern network devices. Instead of requiring proprietary SGT tagging support, the solution uses universal IP address binding to device identifiers, allowing any standard network device to enforce security policies without proprietary extensions.
Solution Approach 2:
The patent changes the identification parameter from proprietary SGT tags to standard IP addresses combined with device identifiers. By changing the identification parameter to something universally supported (IP addresses that all network devices already handle), the solution achieves traffic identification without requiring proprietary support on network nodes.
4Reliability
If manual IP address mapping is performed for firewall policies, then security control is achieved, but administrative burden increases significantly
Solution Approach 1:
The patent enables the network infrastructure to automatically maintain the mapping between IP addresses and device identifiers through self-service mechanisms. The MME or gateway automatically populates and updates the mapping table as IP addresses are assigned and released, eliminating the need for administrators to manually track and update IP address mappings when devices connect or disconnect.
Solution Approach 2:
The patent performs preliminary action by pre-establishing the binding relationship between device identifiers and IP addresses in the network infrastructure before security policy enforcement is needed. The mapping is created and maintained in advance through standard network procedures, so when security policies need to be enforced, the identification is already available without requiring real-time manual mapping.
Data Source
AI summary
A method in a system for providing information about an association between an IP address of a UE and an ICCID of a SIM card used in the UE in a first security domain to an entity in a second security domain. The system comprises a MME, an HSS and a PDN-GW. The method comprises the MME retrieving at least the ICCID and optionally an IP address for the UE from the HSS, and sending the ICCID and optionally the IP address towards the PDN-GW. The method comprises the HSS receiving a request from the MME, and sending the ICCID and optionally the IP address to the MME. Still further, the method comprises the PDN-GW receiving the ICCID and optionally the IP address, if no IP address is received then the PDN-GW assigning an IP address, associating the IP address with the ICCID and informing the entity in the second security domain about the association between the IP address and ICCID in the first security domain.


