Network Access Service via Untrusted WLANs and Secure Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The deployment of WLANs in private homes, offices, and campuses is underutilized due to security risks and lack of commercial benefit, preventing their resources from being utilized for public network access, and existing non-3GPP access solutions require dual-mode UEs and trusted networks, limiting convenience and cost-effectiveness.

Innovation Solution

A network access service provider integrates multiple access networks, allowing untrusted WLANs to contribute resources through secure registration and communication with SGWs, enabling untrusted access without a cellular subscription, using separate network sections and secure tunnels for user data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If untrusted non-3GPP access networks are deployed to provide public network access, then network coverage and convenience are improved, but security risks increase

Engineering Contradiction:
Improvenetwork access coverageVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an untrusted non-3GPP access network as an intermediary between the user equipment and the 3GPP core network. This intermediary network (WLAN, WiMAX, or fixed access network) provides public access while the 3GPP network maintains security control through the ePDG gateway, resolving the contradiction between broad access coverage and security maintenance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trusted non-3GPP access networks are deployed, then security is improved, but deployment cost and complexity increase

Engineering Contradiction:
Improvesecurity trustVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables operators to deploy untrusted non-3GPP access networks with lower investment requirements compared to building fully trusted networks. The operator can leverage existing public WLAN infrastructure without the high cost of deploying dedicated secure access points, reducing deployment complexity while maintaining acceptable security through gateway-based control.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If cellular network infrastructure is deployed to provide mobile services, then service reliability is improved, but deployment cost increases

Engineering Contradiction:
Improveservice reliabilityVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges cellular 3GPP network infrastructure with untrusted non-3GPP access networks (WLAN, WiMAX, fixed access) to provide integrated mobile services. This combination allows operators to leverage existing cellular core network investments while adding flexible wireless access points, reducing overall deployment cost compared to building separate infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If private WLAN networks are made available for public access, then network resource utilization is improved, but security and commercial benefit are compromised

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the 3GPP network monitors and controls access to untrusted non-3GPP networks. The network can authenticate users, manage sessions, and enforce policies on the untrusted access network, providing security feedback loops that enable safe public access to private WLAN resources.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3868152B1System and method for a network access service
Publication Date: 2025.08.13 TAIWAN SEMICONDUCTOR MANUFACTURING CO LTD
  • EP3868152B1 patent drawingFigure 1
  • EP3868152B1 patent drawingFigure 2
  • EP3868152B1 patent drawingFigure 3A

AI summary

A network access system providing network access to a mobile terminal or other device via an untrusted access point such as a wireless access point in an untrusted network. The access point registers with a service gateway, and the wireless terminal connects with the access point and receives a first network address for use with the service gateway. The terminal registers with the service gateway via the access point, and a context identity is maintained at the service gateway, associating the terminal with the access point for the duration of the connection. The terminal can then access a wider network through the service gateway. The service gateway may maintain billing and reward data associated with the context identity.