Mobile Network Security Credential for Roaming Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices associated with multiple identifiers, such as those using embedded universal integrated circuit cards (eUICC), often fail to access private networks when roaming onto different mobile networks due to authorization issues, as the private packet data network (PDN) gateway (PGW) denies access based on the incorrect identifier associated with the foreign network.
Innovation Solution
A security device within the mobile network generates and transmits a security credential to the mobile device, which is then used to authenticate and authorize access to the private network, even when the mobile device is connected to a different mobile network, by determining the correct identifier associated with the mobile device and verifying it against stored credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a mobile device uses multiple identifiers for different mobile networks, then the device can roam between networks, but the private network gateway cannot correctly identify the device for authorization
Solution Approach 1:
The system performs preliminary actions by generating and transmitting the security credential to the mobile device before the device attempts to access the private network while roaming. This advance preparation ensures that when the device connects to a foreign network and requests private network access, the correct home network identifier is already associated with the device through the pre-transmitted security credential, allowing the private network gateway to correctly identify and authorize the device.
2Ease of operation
If the private network gateway uses the identifier from the foreign network, then the device can connect to the network, but the device is incorrectly denied access to the private network
Solution Approach 1:
The security credential acts as an intermediary that bridges the foreign network identifier and the home network identifier. When the mobile device connects to the foreign network, the security credential transmitted in advance contains the home network identifier, allowing the private network gateway to use this intermediary credential to correctly identify the device's home network affiliation and authorize access to the private network, rather than incorrectly using the foreign network identifier.
Data Source
AI summary
A device may determine whether a mobile device is associated with a first identifier that is associated with a first mobile network based on determining that a second identifier associated with the mobile device is associated with a second mobile network. The first identifier may provide authorization for the mobile device to a private network associated with the first mobile network. The device may transmit, based on determining that the mobile device is associated with the first identifier, a security challenge to the mobile device. The device may determine, based on receiving a response to the security challenge from the mobile device, whether the response to the security challenge satisfies the security challenge. The device may provide, based on determining that the response to the security challenge satisfies the security challenge, the mobile device with access to the private network.


