IP Address and ICCID Association for Mobile Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control methods for mobile communication devices face challenges in managing network security across different communication networks or security domains, particularly due to dynamic IP address assignments and the complexity of security administration, which leads to increased administrative burdens and unnecessary transport overhead when confidentiality and integrity protection are not required.

Innovation Solution

A system and method utilizing a Mobility Management Entity (MME), Packet Data Network Gateway (PDN-GW), and Home Subscriber Server (HSS) to provide a secure association between a User Equipment's (UE) IP address and its Integrated Circuit Card Identifier (ICCID) across security domains, eliminating the need for overlay security mechanisms like VPNs when no confidentiality and integrity protection is needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP address-based access control is used, then network security control is implemented, but administrative complexity increases due to dynamic IP address assignments

Engineering Contradiction:
Improvenetwork security controlVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mapping system that associates dynamic IP addresses with static device identifiers (MAC addresses, IMEI, ICCID). This intermediary layer allows security policies to be defined based on device identity rather than transient IP addresses, eliminating the need for manual IP address mapping and policy updates when IP addresses change.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual mapping table that copies and stores the relationship between IP addresses and device identifiers in the network infrastructure (e.g., in the MME or gateway). This copied information allows security devices to enforce policies based on device identity without needing real-time knowledge of current IP address assignments, simplifying administration.

Inventive Principle:
Principle #26Copying

2Reliability

If VPN techniques are applied for security, then authentication and security control are improved, but transport overhead and complexity increase

Engineering Contradiction:
Improveauthentication and security controlVSAvoidtransport overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the authentication and identification function from the VPN overlay mechanism and implements it natively at the IP layer using standard IP address assignment and filtering. By taking out the VPN-specific authentication layer and using core network authentication (HSS/AAA) combined with IP address binding to device identifiers, the solution achieves security control without VPN transport overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses standard, widely-deployed network infrastructure components (MME, HSS, gateway) that already perform authentication and IP address management, rather than deploying expensive VPN infrastructure. The solution leverages existing short-lived IP address assignments combined with device identifier binding, avoiding the need for persistent VPN tunnels and associated overhead.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If domain-based security policies are implemented, then traffic identification based on SGT is improved, but proprietary support is required on all network nodes

Engineering Contradiction:
Improvetraffic identificationVSAvoidproprietary support requirement
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes the security identification mechanism universal by using standard IP address assignment and filtering capabilities that are already present in all modern network devices. Instead of requiring proprietary SGT tagging support, the solution uses universal IP address binding to device identifiers, allowing any standard network device to enforce security policies without proprietary extensions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the identification parameter from proprietary SGT tags to standard IP addresses combined with device identifiers. By changing the identification parameter to something universally supported (IP addresses that all network devices already handle), the solution achieves traffic identification without requiring proprietary support on network nodes.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If manual IP address mapping is performed for firewall policies, then security control is achieved, but administrative burden increases significantly

Engineering Contradiction:
Improvesecurity controlVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables the network infrastructure to automatically maintain the mapping between IP addresses and device identifiers through self-service mechanisms. The MME or gateway automatically populates and updates the mapping table as IP addresses are assigned and released, eliminating the need for administrators to manually track and update IP address mappings when devices connect or disconnect.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary action by pre-establishing the binding relationship between device identifiers and IP addresses in the network infrastructure before security policy enforcement is needed. The mapping is created and maintained in advance through standard network procedures, so when security policies need to be enforced, the identification is already available without requiring real-time manual mapping.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9730074B2System, methods and apparatuses for providing network access security control
Publication Date: 2017.08.08 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9730074B2 patent drawing
  • US9730074B2 patent drawing
  • US9730074B2 patent drawing

AI summary

A method in a system for providing information about an association between an IP address of a UE and an ICCID of a SIM card used in the UE in a first security domain to an entity in a second security domain. The system comprises a MME, an HSS and a PDN-GW. The method comprises the MME retrieving at least the ICCID and optionally an IP address for the UE from the HSS, and sending the ICCID and optionally the IP address towards the PDN-GW. The method comprises the HSS receiving a request from the MME, and sending the ICCID and optionally the IP address to the MME. Still further, the method comprises the PDN-GW receiving the ICCID and optionally the IP address, if no IP address is received then the PDN-GW assigning an IP address, associating the IP address with the ICCID and informing the entity in the second security domain about the association between the IP address and ICCID in the first security domain.