Mobile Station Authentication via SMS Token Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for authenticating mobile stations in unlicensed radio access networks require maintaining preconfigured lists and continuous monitoring, which are inefficient and dependent on specific rules, and do not allow for dynamic validation of access requests without referencing subscriber records.
Innovation Solution
A method that utilizes an existing authenticated communications session to authenticate a mobile station by transmitting instructions or tokens via messages like SMS or MMS, allowing authentication without maintaining subscriber records and enabling handover between networks if authentication is incomplete.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If preconfigured lists of permitted and barred network operator identities are maintained and updated from a provisioning system, then authorisation of access requests can be performed, but the system complexity increases and requires continual maintenance
Solution Approach 1:
The patent extracts the authorisation decision logic from the access controller and moves it to the mobile station itself. The access controller only needs to check a simple flag indicating whether the mobile station is authorised, rather than maintaining and processing complex preconfigured lists of permitted and barred network operator identities. This extraction significantly reduces the provisioning system complexity while maintaining reliable authorisation capability.
2Reliability
If the screening module monitors and processes data passing between the access network and the mobile station to determine patterns of acceptable and non-acceptable behaviour, then access control can be performed, but continual processing on the part of the access network is required
Solution Approach 1:
The patent implements self-service by enabling the mobile station to autonomously determine its own authorisation status and make authorisation decisions. The mobile station independently evaluates whether it is authorised to access the network based on stored authorisation information, eliminating the need for continual monitoring and processing by the access network's screening module. This dramatically improves network processing efficiency while maintaining reliable access control.
3Reliability
If subscriber identity is compared with a preconfigured list of network operator identities, then authorisation can be determined, but the list requires maintenance and updates from a provisioning system
Solution Approach 1:
The patent applies preliminary action by having the mobile station obtain and store authorisation information from its home network before attempting to access a visited network. This authorisation information includes pre-evaluated data about whether the mobile station is authorised to access specific networks. When the mobile station later attempts to access a visited network, it can immediately use this pre-stored information to determine authorisation without requiring real-time comparison with maintained lists, thereby eliminating list maintenance time while preserving authorisation accuracy.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of telecommunication systems that can be accessed via an unlicensed-radio access network, and is particularly, but not exclusively, related to the authorisation and registration of a mobile terminal via unlicensed radio access networks. Embodiments of the present invention provide a method of authenticating a request for access to a telecommunications system which involves App (10) receiving at least two messages: a registration request, and a predetermined message (such as an SMS with token details). The App (10) receives a registration request message from the mobile station (S2.2), and transmits a rejection message in response to the receipt of the registration request message (S2.5), without referring to any subscriber specific records. Further, once the App (10) has received the registration request the App (10) checks the registration request in step (S2.3) and stores (S2.4) an identifier relating to the mobile station from which the registration request came. When the App (10) receives a predetermined message from a network node (S4.1), the App (10) determines whether an identity in the message matches the stored identifier (S4.2 and S4.3). If it does, the App (10) completes the authentication of the mobile station, by sending a message to permit registration (S4.4).