Non-IP APN Authorization for Wireless IoT Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authorization techniques for non-internet protocol (IP) data delivery (NIDD) services in LTE and 5G networks face operational challenges, such as complexity in provisioning, security vulnerabilities, and fraud risks due to the need for specific organization-specific access point names (APNs) and third-party application server involvement.
Innovation Solution
A two-step authorization process using a generic non-IP APN for initial network authorization and a specific non-IP APN with an APN Originating Identifying Anchor (OIA) for secondary authorization within the network, eliminating the need for device management systems and reducing exposure of sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authorization techniques using organization-specific APNs are used, then security and fraud prevention are improved, but device complexity and provisioning burden increase
Solution Approach 1:
The authorization process is segmented into two distinct steps: (1) initial network authorization using a generic non-IP APN, and (2) secondary authorization within the network using a specific non-IP APN with OIA. This segmentation allows security to be maintained through the second step while simplifying device provisioning through the first step.
Solution Approach 2:
The generic non-IP APN acts as an intermediary that enables initial network access without requiring organization-specific credentials on the device. The specific non-IP APN with OIA then serves as the mediator for secondary authorization, separating the provisioning burden from the security enforcement.
2Reliability
If organization-specific non-IP APNs are provisioned on UEs, then service authorization is improved, but ease of operation deteriorates due to provisioning burden
Solution Approach 1:
The UE performs preliminary authorization with the generic non-IP APN before the network establishes the specific non-IP APN connection. This preliminary action enables initial access and setup without requiring organization-specific APNs to be pre-provisioned on the device, reducing provisioning burden while maintaining service authorization through the subsequent secondary authorization step.
Solution Approach 2:
The network automatically performs secondary authorization using the specific non-IP APN with OIA without requiring manual intervention or pre-provisioning on the UE. The system self-services the authorization process by establishing the specific APN connection and performing validation within the network infrastructure.
3Adaptability or versatility
If third-party application servers are involved in authorization, then service coordination is improved, but security vulnerabilities and fraud risks increase
Solution Approach 1:
The critical security function of authorization is extracted from the third-party application server and relocated to the network infrastructure. The application server retains its coordination role while the network performs the actual authorization using the specific non-IP APN with OIA, removing the security vulnerability of having external servers handle authorization.
Solution Approach 2:
The network infrastructure acts as an intermediary between the application server and the UE for the authorization process. The application server coordinates service setup while the network mediates the actual security validation, preventing direct exposure of authorization credentials to third-party servers and reducing fraud risks.
4Ease of operation
If specific non-IP APNs are exposed to application servers, then service setup is improved, but information security deteriorates
Solution Approach 1:
The specific non-IP APN with OIA is maintained with restricted access quality - it is used for authorization within the network infrastructure but not exposed to external application servers. This local quality approach allows the APN to serve its security function while preventing unauthorized exposure of sensitive information.
Solution Approach 2:
The network infrastructure serves as an intermediary that uses the specific non-IP APN for authorization without exposing it to application servers. The mediator role ensures that sensitive authorization credentials remain within the secure network boundary while still enabling service coordination through controlled interfaces.
Data Source
AI summary
A method for authorizing a non-IP data delivery service may include receiving a request from a user equipment device (UE) to attach to an access network based on a generic non-internet protocol (IP) access point name (APN), and performing an initial service authorization of the UE for a non-IP data delivery (NIDD) service with the generic non-IP APN. The method may further include generating a specific non-IP APN by combining the generic non-IP APN with an APN originating identifying anchor (OIA), where the APN OIA identifies an organization associated with the NIDD service. The method may include performing a secondary service authorization of the UE within the access network using the APN OIA, and notifying an application server (AS) of the UE availability for the NIDD service using the generic non-IP APN.


