Mobile Network Security Credential for Roaming Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices associated with multiple identifiers, such as those using embedded universal integrated circuit cards (eUICC), often fail to access private networks when roaming onto different mobile networks due to authorization issues, as the private packet data network (PDN) gateway (PGW) denies access based on the incorrect identifier associated with the foreign network.

Innovation Solution

A security device within the mobile network generates and transmits a security credential to the mobile device, which is then used to authenticate and authorize access to the private network, even when the mobile device is connected to a different mobile network, by determining the correct identifier associated with the mobile device and verifying it against stored credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a mobile device uses multiple identifiers for different mobile networks, then the device can roam between networks, but the private network gateway cannot correctly identify the device for authorization

Engineering Contradiction:
Improvenetwork roaming capabilityVSAvoidauthorization accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by generating and transmitting the security credential to the mobile device before the device attempts to access the private network while roaming. This advance preparation ensures that when the device connects to a foreign network and requests private network access, the correct home network identifier is already associated with the device through the pre-transmitted security credential, allowing the private network gateway to correctly identify and authorize the device.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If the private network gateway uses the identifier from the foreign network, then the device can connect to the network, but the device is incorrectly denied access to the private network

Engineering Contradiction:
Improvenetwork connectionVSAvoidprivate network access authorization
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security credential acts as an intermediary that bridges the foreign network identifier and the home network identifier. When the mobile device connects to the foreign network, the security credential transmitted in advance contains the home network identifier, allowing the private network gateway to use this intermediary credential to correctly identify the device's home network affiliation and authorize access to the private network, rather than incorrectly using the foreign network identifier.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11032326B2Systems and methods for accessing a private network
Publication Date: 2021.06.08 VERIZON PATENT & LICENSING INC
  • US11032326B2 patent drawing
  • US11032326B2 patent drawing
  • US11032326B2 patent drawing

AI summary

A device may determine whether a mobile device is associated with a first identifier that is associated with a first mobile network based on determining that a second identifier associated with the mobile device is associated with a second mobile network. The first identifier may provide authorization for the mobile device to a private network associated with the first mobile network. The device may transmit, based on determining that the mobile device is associated with the first identifier, a security challenge to the mobile device. The device may determine, based on receiving a response to the security challenge from the mobile device, whether the response to the security challenge satisfies the security challenge. The device may provide, based on determining that the response to the security challenge satisfies the security challenge, the mobile device with access to the private network.