Non-SI Device Certificate Access to 3GPP Core Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack a reliable method for non-subscriber identity (non-SI) devices to securely access 3GPP core networks, as they do not have subscriber identity data and are vulnerable to hacking, posing a risk of unauthorized access and billing fraud.
Innovation Solution
A non-SI device establishes an association with an SI device using a two-channel communication system, one being an out-of-band (OOB) channel, to verify and securely share a non-SI public key, followed by obtaining a certificate from a certification authority (CA) to access the core network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If non-SI devices are allowed to access the core network without subscriber identity data, then device connectivity and network access flexibility are improved, but security and risk of unauthorized access deteriorate
Solution Approach 1:
The patent introduces a gateway as an intermediary component between the non-SI device and the core network. The gateway performs authentication and authorization functions, acting as a mediator that enables access for devices without traditional subscriber identity while maintaining security through alternative verification mechanisms.
Solution Approach 2:
The patent changes the authentication parameters from traditional subscriber identity (IMSI, SIM cards) to alternative identification methods suitable for non-SI devices. This includes using device identifiers, certificates, or other credential types that do not require conventional subscriber identity modules.
2Productivity
If non-SI devices access the core network without proper credentials, then network coverage and service availability are improved, but risk of billing fraud and unauthorized access increases
Solution Approach 1:
The patent implements feedback mechanisms where the gateway continuously monitors and verifies device credentials, authentication status, and usage patterns. This real-time feedback loop enables dynamic authorization decisions that prevent billing fraud while maintaining service availability for legitimate non-SI devices.
Solution Approach 2:
The patent performs preliminary authentication and authorization actions before granting network access to non-SI devices. The gateway verifies device credentials and establishes billing parameters in advance, preventing unauthorized access and billing fraud before they can occur.
3Reliability
If traditional SIM-based authentication is used for all devices, then network security is improved, but device complexity and ease of integration for simple devices worsen
Solution Approach 1:
The patent segments the authentication system into two pathways: one for traditional SI devices using SIM cards, and another for non-SI devices using alternative credentials. This segmentation allows simple devices without SIM capabilities to access the network through simplified authentication mechanisms while maintaining security through the gateway's verification processes.
Data Source
AI summary
A non-SI device is arranged for wireless communication and cooperates with an SI device having access to a subscriber identity. The non-SI device has a transceiver to communicate in a local network and a processor to establish an association with the SI. A non-SI public key is provided to the SI device via a first communication channel. A verification code is shared with the SI device via a second communication channel. The channels are different and include an out-of-band channel. Proof of possession of a non-SI private key is provided to the SI device via the first or the second communication channel. From the SI device, a certificate is received that is related to the SI and comprises a signature computed over at least part of the non-SI public key. The certificate reliably enables the non-SI device to access the core network via the local network and a gateway between the local network and the core network.


