Mobile Device Token-Based Secure Tunnel for Core Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for secure access to mobile packet core networks via wireless radio access networks, such as Wi-Fi, are flawed in ensuring authorization and are costly, as they rely on SIM/USIM-based authentication and virtual MSISDN/IMSI solutions that are susceptible to fraud and require significant operational costs and certificate management.
Innovation Solution
A method that uses a token or key stored on the mobile device, generated using TPM and MD5, to establish a secure tunnel connection to the mobile packet core network, which includes a certificate for authentication, MSISDN/vMSISDN, and IMSI/vIMSI, reducing operational costs and enhancing security by preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM/USIM-based authentication methods (EAP-SIM/AKA) are used to ensure secure access to mobile packet core network, then authorization security is improved, but device compatibility is worsened because devices without SIM/USIM cannot access services
Solution Approach 1:
The patent uses virtual MSISDN and virtual IMSI as copies of the actual SIM/USIM identification data. These virtual identifiers are stored in a database and can be used by devices without physical SIM/USIM cards to authenticate and access mobile packet core network services, thereby maintaining security while improving device compatibility
Solution Approach 2:
The patent introduces a database as an intermediary between the authentication entity and the mobile device. The database stores the mapping between virtual MSISDN/IMSI and actual SIM identifiers, enabling devices without SIM/USIM to authenticate through the intermediary database rather than requiring direct SIM-based authentication
2Adaptability or versatility
If virtual MSISDN/IMSI solutions are implemented to enable SIM-less device access, then device compatibility is improved, but security is worsened because credentials can be copied to other devices making them susceptible to fraud
Solution Approach 1:
The patent performs preliminary binding between virtual MSISDN/IMSI and actual SIM identifiers in the database before authentication occurs. This pre-established relationship ensures that even if virtual credentials are copied, they cannot be used without the corresponding valid SIM identifier already registered in the database, preventing fraud
Solution Approach 2:
The authentication entity queries the database during the authentication process to verify the binding between virtual MSISDN/IMSI and actual SIM identifiers. This feedback mechanism ensures that only properly bound virtual credentials are accepted, maintaining security while enabling SIM-less device access
3Reliability
If database queries are performed for each access request to verify virtual MSISDN/IMSI binding, then security is maintained, but operational costs and data traffic are significantly increased
Solution Approach 1:
The patent performs the database binding operation once during initial setup or provisioning, rather than querying the database for every access request. This preliminary action stores the authentication credentials locally, reducing subsequent data traffic and operational costs while maintaining security through the pre-established binding verification
Data Source
AI summary
A method is provided for using a service of a mobile packet core network in a communication system comprising a mobile device, a node, a mobile packet core network and a wireless radio access network. The mobile device accesses the mobile packet core network via the wireless radio access network. During setup of a connection of the mobile device to the wireless radio access network, the mobile device determines whether the wireless radio access network is trustworthy. If it is not trustworthy, the mobile device establishes a secure tunnel connection to the node of the communication system for triggering usage of the service of communication system by an authentication entity. The secure tunnel connection is established by using a token stored within the mobile device and received by the node. The token comprises at least a certificate for authentication to the authentication entity and is generated using general security mechanisms (e.g., TPM and/or MD5).


