Mobile Device Token-Based Secure Tunnel for Core Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure access to mobile packet core networks via wireless radio access networks, such as Wi-Fi, are flawed in ensuring authorization and are costly, as they rely on SIM/USIM-based authentication and virtual MSISDN/IMSI solutions that are susceptible to fraud and require significant operational costs and certificate management.

Innovation Solution

A method that uses a token or key stored on the mobile device, generated using TPM and MD5, to establish a secure tunnel connection to the mobile packet core network, which includes a certificate for authentication, MSISDN/vMSISDN, and IMSI/vIMSI, reducing operational costs and enhancing security by preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM/USIM-based authentication methods (EAP-SIM/AKA) are used to ensure secure access to mobile packet core network, then authorization security is improved, but device compatibility is worsened because devices without SIM/USIM cannot access services

Engineering Contradiction:
Improveauthorization securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent uses virtual MSISDN and virtual IMSI as copies of the actual SIM/USIM identification data. These virtual identifiers are stored in a database and can be used by devices without physical SIM/USIM cards to authenticate and access mobile packet core network services, thereby maintaining security while improving device compatibility

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a database as an intermediary between the authentication entity and the mobile device. The database stores the mapping between virtual MSISDN/IMSI and actual SIM identifiers, enabling devices without SIM/USIM to authenticate through the intermediary database rather than requiring direct SIM-based authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If virtual MSISDN/IMSI solutions are implemented to enable SIM-less device access, then device compatibility is improved, but security is worsened because credentials can be copied to other devices making them susceptible to fraud

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary binding between virtual MSISDN/IMSI and actual SIM identifiers in the database before authentication occurs. This pre-established relationship ensures that even if virtual credentials are copied, they cannot be used without the corresponding valid SIM identifier already registered in the database, preventing fraud

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication entity queries the database during the authentication process to verify the binding between virtual MSISDN/IMSI and actual SIM identifiers. This feedback mechanism ensures that only properly bound virtual credentials are accepted, maintaining security while enabling SIM-less device access

Inventive Principle:
Principle #23Feedback

3Reliability

If database queries are performed for each access request to verify virtual MSISDN/IMSI binding, then security is maintained, but operational costs and data traffic are significantly increased

Engineering Contradiction:
ImprovesecurityVSAvoidoperational costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent performs the database binding operation once during initial setup or provisioning, rather than querying the database for every access request. This preliminary action stores the authentication credentials locally, reducing subsequent data traffic and operational costs while maintaining security through the pre-established binding verification

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10805473B2Triggering a usage of a service of a mobile packet core network
Publication Date: 2020.10.13 VODAFONE GMBH
  • US10805473B2 patent drawing
  • US10805473B2 patent drawing
  • US10805473B2 patent drawing

AI summary

A method is provided for using a service of a mobile packet core network in a communication system comprising a mobile device, a node, a mobile packet core network and a wireless radio access network. The mobile device accesses the mobile packet core network via the wireless radio access network. During setup of a connection of the mobile device to the wireless radio access network, the mobile device determines whether the wireless radio access network is trustworthy. If it is not trustworthy, the mobile device establishes a secure tunnel connection to the node of the communication system for triggering usage of the service of communication system by an authentication entity. The secure tunnel connection is established by using a token stored within the mobile device and received by the node. The token comprises at least a certificate for authentication to the authentication entity and is generated using general security mechanisms (e.g., TPM and/or MD5).