MVNO SIM Identity Authentication Without MNO Core Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile virtual network operators (MVNOs) lack control over authentication mechanisms and face latency and security issues when transitioning between network types, leading to dropped or corrupted packets during communication sessions.
Innovation Solution
MVNOs utilize their own equipment to generate and manage public-private key pairs for encrypting subscriber identity module (SIM) identities, enabling secure and efficient authentication of user devices without relying on Mobile Network Operator (MNO) infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MVNO sends authentication request messages to MNO mobile core, then authentication can be performed, but additional message overhead and latency are introduced
Solution Approach 1:
The patent extracts the authentication function from the MNO mobile core and relocates it to MVNO-controlled equipment. The MVNO provisions public-private key pairs to user devices and performs authentication independently, removing the need to send authentication requests to the MNO core network. This extraction eliminates the message overhead and latency associated with MNO involvement while maintaining authentication reliability.
Solution Approach 2:
The patent introduces public-private key pairs as an intermediary mechanism for authentication. Instead of direct communication between MVNO and MNO core, encrypted identity information served as the intermediary that enables the MVNO to verify user device authenticity independently. This intermediary approach allows authentication to occur without real-time MNO involvement, reducing latency while preserving security.
2Reliability
If MVNO relies on MNO infrastructure for authentication, then security can be maintained, but control over authentication mechanisms is lost
Solution Approach 1:
The patent enables the MVNO to perform authentication independently using self-provisioned public-private key pairs. The MVNO provisions cryptographic credentials to user devices, stores authentication data locally in its own database, and verifies identities without requiring MNO infrastructure. This self-service approach grants the MVNO full control over authentication mechanisms while maintaining security through cryptographic verification.
3Adaptability or versatility
If handover between network types is performed, then network flexibility is maintained, but packet loss or corruption can occur due to connection time
Solution Approach 1:
The patent implements preliminary authentication by provisioning public-private key pairs to user devices before network handover is needed. The encrypted identity information is pre-stored in the user device and MVNO database, enabling immediate verification during handover without requiring real-time authentication requests. This preliminary preparation eliminates authentication latency during network transitions, preventing packet loss while maintaining the ability to switch between network types.
Data Source
AI summary
An MVNO utilizes MNVO-controlled equipment to control generation of public-private key pairs, provisioning of user devices using a public-private key pair, and authenticating user devices requesting access to an MVNO network using the public-private key pair. An MNVO-controlled provisioning server can use a key of a public-private key pair to encrypt a SIM-based identity that is associated with a user device. When the user device requests access to an MVNO network, an MNVO-controlled authentication server requests an encrypted SIM-based identity from the user device and uses a key to decrypt the SIM-based identity as part of determining whether to grant MVNO network access to the user device. Encrypted SIM-based identities enable an MVNO to rely on MVNO-controlled equipment when authenticating user devices to access MVNO network without the additional message overhead accumulated when an MNO mobile core is required to determine whether to grant access to user devices.


