Network Authentication Fallback via PMSI Re-Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing network access process in mobile communication systems does not provide a method for the home network to handle failures in signature authentication, leading to incomplete authentication and potential service disruptions.
Innovation Solution
A network access authentication method that involves receiving a confirmation message with a signature token, verifying its validity, and if invalid, obtaining the Privacy enhanced Mobile Subscriber Identifier (PMSI) to re-perform authentication, including generating a new PMSI and re-authenticating using a second signature token, ensuring proper authentication and service access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the home network does not provide a method to handle signature authentication failures, then the authentication process remains simple, but the reliability of network access is compromised due to incomplete failure handling
Solution Approach 1:
The patent applies preliminary action by pre-defining multiple authentication methods (first authentication based on signature token, second authentication based on PMSI) and failure handling procedures in advance. When signature authentication fails, the system immediately transitions to the pre-prepared PMSI-based authentication method, ensuring continuous authentication capability without ad-hoc decision making.
Solution Approach 2:
The patent implements beforehand cushioning by preparing alternative authentication mechanisms (PMSI-based authentication) in advance to cushion against signature authentication failures. The home network maintains both authentication methods ready, so when one fails, the other can immediately take over, preventing service disruption and ensuring reliable network access.
2Reliability
If the system uses PMSI re-authentication when signature authentication fails, then the network access reliability improves, but the authentication processing time increases
Solution Approach 1:
The system performs preliminary action by pre-computing and storing PMSI values alongside signature tokens during initial authentication setup. When signature authentication fails, the PMSI-based authentication can immediately proceed without requiring time-consuming re-computation or additional network queries, thus minimizing the time loss while ensuring reliable fallback authentication.
3Stability of the object's composition
If the home network implements comprehensive failure handling with PMSI re-authentication, then the service continuity is improved, but the device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the authentication process into distinct segments: first authentication segment using signature tokens, and second authentication segment using PMSI. Each segment has its own verification logic and failure handling procedures. This segmentation allows the home network to implement comprehensive failure handling through modular, manageable components rather than a monolithic complex system.
Solution Approach 2:
The patent uses PMSI as an intermediary authentication mechanism that bridges the gap between initial signature-based authentication and final network access. When signature authentication fails, PMSI serves as an intermediary fallback method that maintains service continuity without requiring complete re-authentication or complex procedural changes in the home network.
Data Source
AI summary
Embodiments of the present disclosure provide a network access authentication processing method and device. The method includes: receiving a confirmation message sent by user equipment, the confirmation message carrying a first signature token generated by the user equipment according to a first Privacy enhanced Mobile Subscriber Identifier (PMSI); verifying whether the first signature token is valid; and when the first signature token is invalid, obtaining the PMSI to perform network access authentication on the user equipment.


