Mutual Authentication in Isolated Public Safety Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, especially for public safety, there is a challenge in providing secure authentication for User Equipment (UE) when an Evolved Node B (eNodeB) is not connected to the core network, as conventional methods lack robustness and expose subscription credentials to security risks, especially in isolated E-UTRAN operation modes without backhaul connectivity.

Innovation Solution

The solution involves an apparatus and method for authenticating a User Equipment (UE) with a local Evolved Packet Core (EPC) using a dedicated IOPS USIM application activated by an IOPS PLMN ID, which includes receiving an IOPS PLMN ID, activating the USIM, and performing mutual authentication between the UE and the eNodeB, utilizing a token-based authentication process to ensure secure communication and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods are used in isolated E-UTRAN mode without backhaul connectivity, then authentication can be performed locally, but security risks increase due to exposure of subscription credentials

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication credentials are segmented into two parts: a first set of credentials stored in the UE and a second set of credentials stored in the eNodeB. This segmentation allows mutual authentication without exposing the complete subscription credentials, resolving the contradiction between maintaining authentication capability and reducing security risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A token-based intermediary mechanism is introduced where the eNodeB provides a token to the UE for authentication. This token acts as an intermediary that enables verification without directly exposing the underlying subscription credentials, thereby maintaining security while enabling authentication in isolated mode.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If complete subscriber database is stored in eNodeB for authentication, then authentication can be performed autonomously, but device complexity and security risks increase

Engineering Contradiction:
Improveautonomous operation capabilityVSAvoideNodeB configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The complete subscriber database is extracted from the eNodeB and stored instead in the UE. The eNodeB retains only a second set of credentials and token-generation capability, significantly reducing its complexity while still enabling autonomous authentication through the token mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The UE performs self-service authentication by using its stored first set of credentials to verify the token provided by the eNodeB. This eliminates the need for the eNodeB to store complete subscriber databases, reducing complexity while maintaining autonomous operation capability.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If token-based authentication is implemented, then security is improved, but authentication process complexity increases

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidauthentication protocol
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The first set of credentials is preliminarily stored in the UE before authentication occurs. This preliminary preparation allows the UE to immediately verify tokens without complex real-time database queries, reducing protocol complexity while maintaining security through the pre-configured credential verification capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4033698A1Mutual authentication between user equipment and an evolved packet core
Publication Date: 2022.07.27 SAMSUNG ELECTRONICS CO LTD
  • EP4033698A1 patent drawingFigure 1a
  • EP4033698A1 patent drawingFigure 1b
  • EP4033698A1 patent drawingFigure 2~3

AI summary

A method of operating a User Equipment (UE) enabled isolated Evolved Universal Mobile Telecommunications System Terrestrial Radio Access Network (E-UTRAN) operation for public safety (IOPS) is provided. The method includes receiving, from an IOPS-capable eNodeB (eNB), a system information block (SIB) message including an IOPS public land mobile network (PLMN) identity; activating a dedicated IOPS universal subscriber identity module (USIM) application based on the IOPS PLMN identity; and authenticating the IOPS-capable eNB based on the dedicated IOPS USIM application.