Mobile Terminal WLAN Access via SIM-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for enabling mobile terminals to access wireless local area networks require user interaction for credential transmission, especially during initial access, and face challenges in securely providing encryption keys for private networks, with existing solutions like EAP-SIM and WPS being cumbersome or limited in their applicability.

Innovation Solution

The method involves exchanging authentication information between a public land mobile network and a mobile terminal using a WLAN login client and server module, allowing automatic access to wireless local area networks without user intervention, by storing and managing authentication data within the mobile terminal's SIM card, enabling secure and convenient access to both public and private networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credentials are transmitted to mobile terminal for first time access to wireless local area network, then access to wireless local area network is enabled, but user interaction is required which increases complexity and time consumption

Engineering Contradiction:
Improveaccess to wireless local area networkVSAvoiduser interaction required
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-configuring authentication credentials in the mobile terminal before actual WLAN access is needed. The terminal receives and stores authentication data (such as SIM-based credentials or pre-shared keys) in advance through the cellular network, so that when the terminal needs to access a WLAN, the authentication is already prepared and can be automatically applied without requiring user interaction during the actual connection process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the cellular network as an intermediary to deliver authentication credentials to the mobile terminal. Instead of requiring direct user input or complex local configuration, the authentication data is transmitted through the trusted cellular network infrastructure (via SMS, data channel, or SIM card mechanisms), which acts as a secure mediator to provide the credentials automatically to the terminal's WLAN client.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are provided to mobile terminal for private wireless local area network, then secure access is enabled, but secure transmission of credentials becomes complex

Engineering Contradiction:
Improvesecure access to private wireless local area networkVSAvoidtransmission of encryption keys
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cellular network serves as a secure intermediary channel for transmitting encryption keys and authentication credentials to the mobile terminal. The cellular infrastructure provides a trusted communication path that is more secure than over-the-air WLAN transmission, allowing sensitive cryptographic material to be delivered without exposing it to eavesdropping or tampering risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The mobile terminal automatically receives, stores, and manages the encryption keys without requiring user intervention. The terminal's WLAN client autonomously configures itself with the provided credentials and performs the encryption/decryption operations, making the security management transparent to the user while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If automatic access to wireless local area network is implemented, then user interaction is eliminated, but authentication information must be pre-configured in mobile terminal

Engineering Contradiction:
Improveaccess to wireless local area networkVSAvoidauthentication information storage
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent leverages the SIM card's existing authentication infrastructure to serve multiple purposes. The SIM card, originally designed for cellular network authentication, is also used to store and provide authentication credentials for WLAN access. This multi-functional use of the SIM card eliminates the need for separate credential storage mechanisms, achieving automation without significantly increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile terminal automatically manages the authentication process by storing credentials in the SIM card and autonomously retrieving and applying them when WLAN access is required. The terminal's WLAN client self-configures using the SIM-based credentials without user intervention, making the entire authentication process automatic while utilizing existing secure storage infrastructure.

Inventive Principle:
Principle #25Self-service

4Reliability

If existing authentication mechanisms like EAP-SIM and WPS are used, then access control is provided, but the processes are cumbersome and have limited applicability

Engineering Contradiction:
Improveaccess control to wireless local area networkVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the mobile terminal automatically performs the authentication process using SIM-based credentials without requiring user actions such as button pressing (WPS) or manual credential entry (EAP-SIM). The terminal autonomously initiates the authentication exchange with the WLAN access point and completes the process transparently, eliminating the operational burden of existing mechanisms while maintaining their security benefits.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The solution creates a universal authentication mechanism that works across different WLAN types (public and private networks) by using SIM-based credentials that can be applied in various authentication scenarios. Unlike WPS which requires specific AP support or EAP-SIM which needs particular network configurations, this approach provides broad compatibility across different WLAN infrastructures while simplifying the user experience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2453608B1Method and devices for accessing a wireless local area network
Publication Date: 2015.01.07 DEUTSCHE TELEKOM AG
  • EP2453608B1 patent drawingFigure 1~2
  • EP2453608B1 patent drawingFigure 3~4

AI summary

The present invention relates to a method, a public land mobile network, a mobile terminal and a program for enabling a mobile terminal (20) to have access to a wireless local area network (30) via a first radio interface (21) of the mobile terminal, wherein the wireless local area network requires at least one authentication information to grant access to the mobile terminal, wherein the mobile terminal comprises a subscriber identity module (23) and a second radio interface (22) to a public land mobile network, (10) wherein the public land mobile network comprises a WLAN login server (15) module, and wherein the mobile terminal comprises a WLAN login client module (25), wherein the method comprises the step of: -- transmitting a first set of data from the WLAN login server module (15) of the public land mobile network (10) to the mobile terminal (20), the first set of data being related to the authentication information required by the wireless local area network (30), -- storing a second set of data related to the authentication information required by the wireless local area network (30) within the subscriber identity module (23) of the mobile terminal using the WLAN login client module (25), -- in case access to the wireless local area network is requested by the mobile terminal (20), transmitting the authentication information from the mobile terminal to the wireless local area network (30) using the WLAN login client module (25).