Network Access Control via Entity Identifier Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access-control techniques for small-scale networks are inflexible and costly, as they rely on closed subscriber groups (CSGs) and SIM cards, which are difficult to manage and expensive for smaller user groups, and do not scale well from larger cellular-telephone networks.
Innovation Solution
A computer system that restricts access to a private or neutral-host network by using identifiers of radio nodes and electronic devices to determine entity identifiers, allowing authentication based on matching entity identifiers or service provider credentials, thereby enabling controlled access without relying on CSGs or SIM cards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If closed subscriber groups (CSGs) and SIM cards are used for access control in small-scale networks, then access security is improved, but device complexity and management costs increase
Solution Approach 1:
The patent extracts the access control functionality from the traditional CSG/SIM card system and implements it through a simplified identifier matching mechanism. The network equipment maintains a whitelist of allowed device identifiers, and access control is achieved by comparing incoming device identifiers against this whitelist, eliminating the need for complex SIM card-based CSG management.
Solution Approach 2:
The patent changes the access control parameter from complex CSG membership verification to simple identifier matching. Instead of verifying CSG membership through SIM cards and multiple authentication protocols, the system uses direct comparison of device identifiers (such as IMEI or other unique identifiers) against a stored whitelist, significantly simplifying the access control process.
2Reliability
If closed subscriber groups (CSGs) and SIM cards are used for access control in small-scale networks, then access security is improved, but costs increase
Solution Approach 1:
The patent replaces expensive SIM cards and CSG subscription systems with a simpler identifier-based approach. The system uses readily available device identifiers that are already present in mobile devices, eliminating the need for costly SIM card distribution, provisioning, and management infrastructure required by traditional CSG systems.
Solution Approach 2:
The patent extracts the essential access control function from the expensive SIM card/CSC ecosystem and implements it through a lightweight identifier matching mechanism. This extraction eliminates the need for costly SIM card infrastructure while maintaining the core security function of controlling who can access the small-scale network.
3Extent of automation
If access-control techniques from larger cellular-telephone networks are scaled down to small-scale networks, then access control capability is improved, but adaptability worsens
Solution Approach 1:
The patent adapts the access control mechanism to the specific needs of small-scale networks by implementing a localized identifier matching approach. Rather than attempting to scale down the complex hierarchical CSG structure of large networks, the system creates a simplified local access control mechanism that is specifically suited for small-scale deployments with limited numbers of users and devices.
Solution Approach 2:
The patent implements a dynamic access control system where the whitelist of allowed device identifiers can be easily updated and modified. This dynamic approach allows the system to adapt to changing access requirements in small-scale networks, such as adding or removing authorized devices, without requiring complex reconfiguration of CSG membership structures.
Data Source
AI summary
During operation, a computer receives an attachment request from a radio node, where the attachment request is associated with an electronic device, and includes an identifier of the radio node, an identifier of the electronic device and an identifier of a service provider. Then, the computer determines a first entity identifier of an entity based at least in part on the identifier of the radio node and a second entity identifier of the entity based at least in part on the identifier of the electronic device. When the first entity identifier matches the second entity identifier, the computer performs authentication of the electronic device. Alternatively, if the entity identifiers are different, but the identifier of the service provider matches a stored identifier, the computer performs the authentication of the electronic device. Otherwise, the computer does not allow the electronic device to attach to a private or neutral-host network.


