Movable Network Entity Authentication Without Core-Network
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication systems with movable network entities like satellites, establishing an authenticated connection between a terminal entity and a movable network entity is challenging when there is no end-to-end connection to the core-network, as traditional authentication methods rely on core-network entities.
Innovation Solution
The method involves a movable network entity obtaining a security parameter from a terminal entity, establishing a connection based on this parameter, and identifying the terminal entity through a comparison of received and obtained security parameters, even without an end-to-end connection to the core-network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods relying on core-network entities are used, then authentication can be performed in standard network scenarios, but authentication fails when there is no end-to-end connection to the core-network
Solution Approach 1:
The authentication process is segmented into two independent parts: (1) terminal entity sends authentication data directly to the movable network entity, and (2) the movable network entity verifies this data locally using pre-shared security parameters. This segmentation eliminates the mandatory dependency on core-network entities, allowing authentication to function in disconnected scenarios while maintaining reliability through the pre-established security framework.
Solution Approach 2:
The patent introduces a direct communication channel between the terminal entity and movable network entity as an intermediary mechanism. This direct channel bypasses the core-network entity dependency, enabling the terminal entity to transmit authentication data and the movable network entity to perform verification independently, thus adapting to scenarios where core-network connection is unavailable.
2Adaptability or versatility
If local authentication without core-network connection is implemented, then authentication is possible in disconnected scenarios, but the complexity of the authentication mechanism increases
Solution Approach 1:
Security parameters including authentication data and verification keys are pre-shared between the terminal entity and movable network entity before disconnection occurs. This preliminary action during connected phases eliminates the need for complex real-time key exchange mechanisms when disconnected, reducing operational complexity while maintaining adaptability to disconnected scenarios.
Solution Approach 2:
The terminal entity creates a copy of its authentication data and transmits it directly to the movable network entity. This copying mechanism simplifies the authentication process by eliminating complex cryptographic handshakes, as the movable network entity can directly verify the copied authentication data against its pre-stored security parameters.
3Adaptability or versatility
If security parameters are transmitted directly between terminal entity and movable network entity, then authentication can occur without core-network involvement, but the risk of security parameter interception increases
Solution Approach 1:
The patent transforms the authentication mechanism by changing the nature of transmitted parameters from sensitive cryptographic keys to authenticated data that can be verified using pre-shared keys. The terminal entity transmits authentication data that the movable network entity verifies locally using pre-configured security parameters, changing the parameter transmission model to reduce interception risk while maintaining independence from core-network.
Solution Approach 2:
The movable network entity performs self-service authentication by verifying the terminal entity's authentication data against its own pre-stored security parameters without requiring core-network validation. This self-service mechanism reduces the transmission of sensitive security parameters over the air interface, as verification occurs locally using pre-established credentials, thereby reducing interception risk.
Data Source
AI summary
There are provided methods, apparatuses and computer program products for authentication between a movable network entity and a terminal entity. Such provided methods, apparatuses and computer program products may include authentication and/or identification based on sending and/or receiving at least one security parameter and/or at least one authentifier.


