Network Node Authentication Key Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for subscriber transfer between network operators in telecommunication systems are inefficient and costly, as they require replacing the Universal Integrated Circuit Card (UICC) and transferring authentication keys, which compromises security and is time-consuming, especially for Machine-to-Machine (M2M) devices.
Innovation Solution
A method and system that allow seamless subscriber transfer between network operators without replacing the UICC or transferring authentication keys, by routing authentication requests to the original key storage location, maintaining high-security standards and streamlining the porting process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If UICC replacement is used for subscriber transfer between network operators, then subscriber porting can be achieved, but the process becomes time-consuming and costly
Solution Approach 1:
The invention separates the authentication key storage from the UICC by introducing a separate key storage location in the home network. The UICC retains only the subscriber identity (IMSI) while the authentication key (K) is stored independently in the home network's authentication center. This segmentation allows the UICC to be reused across different network operators without key transfer, eliminating the need for UICC replacement during subscriber porting.
2Productivity
If authentication keys are transferred between network operators, then subscriber access can be enabled, but security is compromised
Solution Approach 1:
The invention extracts the authentication key (K) from the UICC and stores it separately in the home network's authentication center. The UICC is left with only the subscriber identity information. When a subscriber ports to a new network operator, the new operator's authentication center retrieves the key from the original home network's storage location, rather than transferring it directly. This extraction and indirect retrieval mechanism maintains security by avoiding direct key exposure during the porting process.
3Ease of operation
If remote IMSI reprogramming is used, then UICC replacement can be avoided, but the process requires original network operator involvement and is complex
Solution Approach 1:
The invention introduces an intermediary mechanism where the new network operator's authentication center communicates with the original home network's authentication center to retrieve the authentication key. This intermediary approach allows IMSI reprogramming to be performed by the new operator without requiring involvement from the original operator, simplifying the operational process while managing the complexity through standardized authentication protocols.
4Productivity
If multiple authentication keys are stored in UICC, then key transfer between operators becomes possible, but UICC security model is compromised
Solution Approach 1:
The invention extracts the authentication key from the UICC entirely, storing it only in the home network's authentication center. The UICC is designed to never contain the authentication key, only the subscriber identity. This fundamental extraction prevents any possibility of key transfer or multiple key storage in the UICC, thereby preserving the UICC security model while enabling seamless subscriber porting through key retrieval from the network side.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
There is provided a method of operating a node (512, 520, 1102) for use by a first network (502, 504), the first network (502, 504) applies an authentication process to allow a subscriber access to a network, wherein authentication information used in the authentication process is derived using a key associated with a subscriber identity of a subscriber, the key being stored in either a location within the first network (502, 504) or external to the first network (502, 504). The method includes storing (400) information regarding the locations at which keys associated with subscriber identities are stored, receiving (402) a request for authentication information, the request indicating the subscriber identity to which the request for authentication information relates, retrieving (404)information regarding the location at which the key associated with the subscriber identity is stored using the subscriber identity, and routing (406) the request for authentication information according to the retrieved information.