Network Authorization Assistance for Radio Access Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in securely verifying the trustworthiness of supplementary radio access networks, such as isolated LTE networks, which can lead to confidentiality and integrity issues due to potential insecure deployment or malicious intentions by network operators, making it difficult to make informed decisions about network access.

Innovation Solution

The implementation of network authorization assistance mechanisms that utilize hierarchically structured network identifiers, like ANIDs, to provide users with trustworthy information for decision-making, including the creation of lists of allowed and disallowed network identifiers, and the use of cryptographic verification to ensure the authenticity of network identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users connect to supplementary radio access networks to gain access to additional network services, then network coverage and service availability are improved, but security and trustworthiness of the network connection deteriorate

Engineering Contradiction:
Improvenetwork service availabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authentication and authorization checks before allowing UE to connect to supplementary networks. The network identifier is verified against authorized lists maintained by the home network, preventing connections to untrusted networks before security issues can arise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The home network acts as an intermediary between the UE and supplementary networks. It maintains authorized and disallowed network identifier lists, and provides authorization assistance to verify whether a supplementary network is trustworthy before the UE connects to it.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If the system provides detailed network identifier information to help users verify network trustworthiness, then user decision-making capability is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork trust informationVSAvoidauthorization system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system extracts only the necessary trust verification information (network identifier presence in authorized/disallowed lists) from the complex authorization process and presents it to the UE in a simple, actionable format. This provides users with essential decision-making information without requiring them to process complex security protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The UE is empowered to make its own connection decisions based on the authorization assistance information provided by the home network. The system provides the necessary information (authorized/disallowed lists) and lets the UE independently determine whether to connect, rather than requiring complex centralized control for each connection decision.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3446518B1Network authorization assistance
Publication Date: 2022.01.05 NOKIA SOLUTIONS & NETWORKS OY
  • EP3446518B1 patent drawingFigure 1
  • EP3446518B1 patent drawingFigure 2
  • EP3446518B1 patent drawingFigure 3

AI summary

There are provided measures for network authorization assistance. Such measures exemplarily comprise detecting a connection opportunity to a radio access network, obtaining a network identifier of said radio access network, said network identifier being indicative of trust related information with respect to said radio access network, verifying correctness of said network identifier, and controlling a selection processing of selecting to connect to said radio access network or not based on said network identifier of said radio access network, if said network identifier is verified as being correct.