Mobile Station Certified Service Record Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile communication systems face delays and vulnerabilities during the authentication and registration process of mobile stations when migrating between networks, particularly due to the need for communication between the home and visited networks, which can be exacerbated by link failures or high traffic.

Innovation Solution

A method where a mobile station receives a certified service record with a Message Authentication Code (MAC) from its home network, allowing it to authenticate and register with a visited network without direct communication between the networks, using a shared MAC key for secure service provision.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the visited network obtains service records from the home network during authentication and registration, then the services provided to the mobile station are accurate and authorized, but the authentication process experiences delays and increased system control traffic

Engineering Contradiction:
Improveservice authorization accuracyVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The mobile station performs preliminary authentication with the home network before visiting the visited network, obtaining and storing authentication credentials in advance. This allows the visited network to authenticate the mobile station locally without needing to contact the home network during the actual registration process, thereby eliminating authentication delays while maintaining service authorization accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile station acts as an intermediary that carries authentication credentials between the home network and visited network. Instead of direct communication between networks during authentication, the mobile station mediates the process by presenting pre-obtained credentials to the visited network, reducing system control traffic while ensuring reliable service authorization

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the visited network communicates with the home network for authentication and service record retrieval, then proper service authorization is ensured, but the system control traffic increases and link failures can prevent registration

Engineering Contradiction:
Improveservice authorization accuracyVSAvoidsystem control traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The authentication credentials and service authorization information are extracted from the home network communication and stored locally in the mobile station's memory. This extraction allows the visited network to perform authentication independently without requiring continuous communication with the home network, thereby reducing system control traffic while maintaining accurate service authorization

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile station performs self-authentication by using credentials already stored in its memory, rather than requiring the visited network to retrieve service records from the home network. This self-service approach eliminates the need for additional network communication during registration, reducing system control traffic while ensuring proper service authorization through locally stored validated credentials

Inventive Principle:
Principle #25Self-service

3Reliability

If direct communication between home and visited networks is maintained for authentication, then service records can be verified, but the process is vulnerable to link failures and congestion

Engineering Contradiction:
Improveservice record verificationVSAvoidlink failure vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Service record verification is performed preliminarily when the mobile station communicates with the home network before visiting the visited network. The authenticated credentials are stored in the mobile station's memory, creating a verified authentication state that is independent of the home network. This preliminary verification eliminates vulnerability to link failures during visited network registration, while service record accuracy is maintained through the pre-verification process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile station cushions against link failure risks by storing validated authentication credentials in its local memory before potentially encountering network issues. This prior cushioning ensures that even if communication links fail or experience congestion during visited network registration, the mobile station can still be authenticated using the pre-stored credentials, maintaining service record verification reliability without being affected by link vulnerabilities

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentEP2332357B1Method, mobile station, system and network processor for use in mobile communications
Publication Date: 2014.02.19 MOTOROLA SOLUTIONS INC
  • EP2332357B1 patent drawingFigure 1
  • EP2332357B1 patent drawingFigure 2

AI summary

A method (200) of operation in a mobile communication system (100) includes: a mobile station (101) sending (207) to a visited network (103) a certified service record, provided by a home network (102), of communication services allowed to be provided to the mobile station, the service record being accompanied by or including a certificate code applied by the home network by a calculation procedure applied to contents of the service record using an authentication key; the visited network calculating (211) an authentication code for the service record using an authentication key obtained by the visited network; the visited network authenticating (212) the service record by matching (212) the certificate and authentication codes; and the visited network providing (215) communication services to the mobile station based upon the authenticated service record.