Non-SI Core Network Access via Two-Channel Device Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack a reliable method for non-subscriber identity (non-SI) devices to securely access core networks, such as 4G/5G cellular networks, without the risk of hacking and unauthorized access.

Innovation Solution

A two-channel communication approach is employed, using a local communication protocol and an out-of-band (OOB) channel to establish an association between a non-SI device and an SI device, involving the exchange of a non-SI public key and verification code, followed by the transmission of security data encrypted with the non-SI public key to ensure secure access to the core network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-SI devices are integrated into core networks using traditional SI-based authentication, then access to core networks is enabled, but security vulnerabilities arise due to lack of proper authentication mechanisms for devices without subscriber identity

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an SI device as an intermediary between the non-SI device and the core network. The SI device holds the subscriber identity and acts as a mediator that provides authentication credentials to the non-SI device, enabling secure access without requiring the non-SI device to have its own SI. This resolves the contradiction by allowing adaptability (non-SI device access) while maintaining reliability (security through SI device mediation).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary association and authentication actions between the non-SI device and the SI device before core network access. The non-SI device establishes an association with the SI device, receives authentication credentials in advance, and performs mutual authentication. This preliminary action ensures security is established before access is granted, resolving the contradiction between enabling access and maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If two-channel communication approach is used for association between non-SI device and SI device, then authentication reliability is improved, but communication complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into two distinct communication channels: a first channel for exchanging association information and a second channel for exchanging authentication credentials. This segmentation allows each channel to be optimized for its specific purpose, improving authentication reliability while making the overall process more manageable despite the increased complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The SI device acts as an intermediary that manages the two-channel communication protocol. It receives requests from the non-SI device, coordinates the exchange of information across both channels, and validates the authentication process. This intermediary role simplifies the implementation complexity by centralizing the protocol management in a trusted entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If non-SI devices establish association with SI devices through multiple communication channels, then security against man-in-the-middle attacks is enhanced, but establishment time increases

Engineering Contradiction:
ImprovesecurityVSAvoidassociation establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary association setup between the non-SI device and SI device before actual core network access. The association information is established in advance through the first communication channel, and authentication credentials are prepared through the second channel. This preliminary action reduces the time required during actual access operations while maintaining the security benefits of multi-channel verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The non-SI device and SI device perform self-verification through mutual authentication using the established association and exchanged credentials. Each device independently verifies the other's authenticity using the information exchanged through the two channels, eliminating the need for additional verification steps and reducing overall establishment time while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4344135B1Non-3GPP device access to core network
Publication Date: 2025.12.24 KONINKLIJKE PHILIPS NV
  • EP4344135B1 patent drawingFigure 1
  • EP4344135B1 patent drawingFigure 2
  • EP4344135B1 patent drawingFigure 3

AI summary

A non-SI device (120) is arranged for wireless communication (130) and cooperates with an SI device (110) having access to a subscriber identity. The non-SI device has a transceiver (121) to communicate in a local network and a processor (122) to establish an association with the SI. A non-SI public key is provided to the SI device via a first communication channel. A verification code is shared with the SI device via a second communication channel. The channels are different and include an out-of-band channel (140). Proof of possession of a non-SI private key is provided to the SI device via the first or the second communication channel. From the SI device, security data is received that is related to the SI and is computed using the non-SI public key. The security data reliably enables the non-SI device to access the core network via the local network and a gateway between the local network and the core network.