Non-SI Device Core Network Access via Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack a reliable method for non-subscriber identity (non-SI) devices to securely access core networks, such as 4G/5G cellular networks, without a SIM card, leaving them vulnerable to hacking and unauthorized access.

Innovation Solution

A system using two distinct communication channels, one in-band and one out-of-band, to establish a secure association between a non-SI device and an SI device, involving the exchange of a public key and verification code, followed by the transmission of security data encrypted with the non-SI public key, ensuring only the non-SI device can access the core network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-SI devices are allowed to access core networks without SIM cards, then device connectivity and internet access are improved, but security against hacking and unauthorized access deteriorates

Engineering Contradiction:
Improvedevice connectivityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an SI device as an intermediary between the non-SI device and the core network. The SI device holds the subscriber identity and acts as a mediator that manages the association and security credentials, allowing non-SI devices to access the network while maintaining security through the intermediary's control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary association steps where the non-SI device and SI device establish a secure relationship before network access is granted. The non-SI public key is provided to the SI device in advance, and security credentials are pre-configured through a defined association sequence, ensuring security is established before connectivity is activated

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If security credentials are transmitted over wireless channels, then device association is simplified, but vulnerability to man-in-the-middle attacks increases

Engineering Contradiction:
Improveassociation processVSAvoidman-in-the-middle attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The SI device serves as a trusted intermediary that mediates the credential exchange process. Instead of direct peer-to-peer transmission that is vulnerable to interception, the SI device receives and verifies the non-SI public key, then provides security credentials back to the non-SI device through the intermediary, protecting against man-in-the-middle attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The non-SI device generates its own public-private key pair and provides the public key to the SI device. The device performs self-identification and self-registration, reducing the attack surface by eliminating the need for the system to push credentials to the device, thereby simplifying the process while maintaining security

Inventive Principle:
Principle #25Self-service

3Reliability

If two different communication channels are used for verification, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidcommunication channels
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses out-of-band communication as an additional dimension for verification. Instead of relying solely on the primary wireless communication channel, a second independent channel (such as NFC, Bluetooth, or visual verification) is introduced to verify the association, providing security through multi-dimensional verification without requiring complex protocols on the primary channel

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP4716272A2Non-3GPP device access to core network
Publication Date: 2026.03.25 KONINKLIJKE PHILIPS NV
  • EP4716272A2 patent drawingFigure 1
  • EP4716272A2 patent drawingFigure 2
  • EP4716272A2 patent drawingFigure 3

AI summary

A non-SI device (120) is arranged for wireless communication (130) and cooperates with an SI device (110) having access to a subscriber identity. The non-SI device has a transceiver (121) to communicate in a local network and a processor (122) to establish an association with the SI. A non-SI public key is provided to the SI device via a first communication channel. A verification code is shared with the SI device via a second communication channel. The channels are different and include an out-of-band channel (140). Proof of possession of a non-SI private key is provided to the SI device via the first or the second communication channel. From the SI device, security data is received that is related to the SI and is computed using the non-SI public key. The security data reliably enables the non-SI device to access the core network via the local network and a gateway between the local network and the core network.