Network Apparatus Authentication for SIM-Free Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In LTE mobile communication systems, there is a risk of providing communication services to SIM-free terminals without proper use authentication, potentially allowing illegitimate devices to access networks, which can lead to unauthorized usage and legal issues.

Innovation Solution

A network apparatus that stores apparatus information associating model identifiers with use authentication status, allowing it to determine whether to provide communication services based on the authentication information, thereby restricting services to unauthenticated terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the network apparatus provides communication services to SIM-free terminals without verifying use authentication, then network accessibility and ease of operation are improved, but security and reliability deteriorate due to potential unauthorized access by illegitimate devices

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network apparatus performs use authentication verification before providing communication services to SIM-free terminals. The apparatus checks whether the terminal apparatus is included in the apparatus information stored in the storage unit, which contains model identifiers and use authentication information. This preliminary verification action prevents unauthorized access while maintaining network accessibility for legitimate devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the network apparatus implements strict use authentication verification for SIM-free terminals, then security and reliability are improved, but device complexity and operational overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication verification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network apparatus uses model identifiers as a simplified representation of terminal apparatus characteristics. Instead of performing complex comprehensive authentication, the apparatus checks whether the terminal's model identifier exists in the stored apparatus information database. This copying approach using identifier matching reduces authentication complexity while maintaining security effectiveness.

Inventive Principle:
Principle #26Copying

3Measurement precision

If the network apparatus stores comprehensive apparatus information for all terminal models, then authentication accuracy is improved, but storage requirements and system complexity increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidstorage information volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The network apparatus extracts and stores only the essential authentication elements in the apparatus information database: model identifiers and use authentication status. By taking out only the necessary identification and authentication state data rather than storing complete terminal specifications, the system achieves accurate authentication while minimizing storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10735417B2Network apparatus
Publication Date: 2020.08.04 KYOCERA CORP
  • US10735417B2 patent drawing
  • US10735417B2 patent drawing
  • US10735417B2 patent drawing

AI summary

A network apparatus according to an embodiment comprises: a storage unit configured to store apparatus information in which information on a model identifier of a terminal apparatus and use authentication information indicating that the terminal apparatus is granted a use authentication by a predetermined network operator are associated; a receiver configured to receive, from another network apparatus, information on a model identifier of a user terminal accessing a network managed by the predetermined network operator; and a controller configured to notify, based on the information on the model identifier of the user terminal and the apparatus information, the other network apparatus of information for determining whether or not to provide a communication service to the user terminal.