Movable Network Entity Authentication Without Core-Network

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication systems with movable network entities like satellites, establishing an authenticated connection between a terminal entity and a movable network entity is challenging when there is no end-to-end connection to the core-network, as traditional authentication methods rely on core-network entities.

Innovation Solution

The method involves a movable network entity obtaining a security parameter from a terminal entity, establishing a connection based on this parameter, and identifying the terminal entity through a comparison of received and obtained security parameters, even without an end-to-end connection to the core-network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods relying on core-network entities are used, then authentication can be performed in standard network scenarios, but authentication fails when there is no end-to-end connection to the core-network

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidadaptability to disconnected scenarios
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication process is segmented into two independent parts: (1) terminal entity sends authentication data directly to the movable network entity, and (2) the movable network entity verifies this data locally using pre-shared security parameters. This segmentation eliminates the mandatory dependency on core-network entities, allowing authentication to function in disconnected scenarios while maintaining reliability through the pre-established security framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a direct communication channel between the terminal entity and movable network entity as an intermediary mechanism. This direct channel bypasses the core-network entity dependency, enabling the terminal entity to transmit authentication data and the movable network entity to perform verification independently, thus adapting to scenarios where core-network connection is unavailable.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If local authentication without core-network connection is implemented, then authentication is possible in disconnected scenarios, but the complexity of the authentication mechanism increases

Engineering Contradiction:
Improveadaptability to disconnected scenariosVSAvoidauthentication mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Security parameters including authentication data and verification keys are pre-shared between the terminal entity and movable network entity before disconnection occurs. This preliminary action during connected phases eliminates the need for complex real-time key exchange mechanisms when disconnected, reducing operational complexity while maintaining adaptability to disconnected scenarios.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal entity creates a copy of its authentication data and transmits it directly to the movable network entity. This copying mechanism simplifies the authentication process by eliminating complex cryptographic handshakes, as the movable network entity can directly verify the copied authentication data against its pre-stored security parameters.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If security parameters are transmitted directly between terminal entity and movable network entity, then authentication can occur without core-network involvement, but the risk of security parameter interception increases

Engineering Contradiction:
Improveindependence from core-networkVSAvoidsecurity parameter interception risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the authentication mechanism by changing the nature of transmitted parameters from sensitive cryptographic keys to authenticated data that can be verified using pre-shared keys. The terminal entity transmits authentication data that the movable network entity verifies locally using pre-configured security parameters, changing the parameter transmission model to reduce interception risk while maintaining independence from core-network.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The movable network entity performs self-service authentication by verifying the terminal entity's authentication data against its own pre-stored security parameters without requiring core-network validation. This self-service mechanism reduces the transmission of sensitive security parameters over the air interface, as verification occurs locally using pre-established credentials, thereby reducing interception risk.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250055884A1Authentication of a terminal entity and a movable network entity
Publication Date: 2025.02.13 NOKIA TECHNOLOGIES OY
  • US20250055884A1 patent drawing
  • US20250055884A1 patent drawing
  • US20250055884A1 patent drawing

AI summary

There are provided methods, apparatuses and computer program products for authentication between a movable network entity and a terminal entity. Such provided methods, apparatuses and computer program products may include authentication and/or identification based on sending and/or receiving at least one security parameter and/or at least one authentifier.