Proof-of-Presence Indicator for Secure PLMN Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless network systems face challenges in securely communicating sensitive user equipment (UE) information across public land mobile networks (PLMNs), as unauthorized parties can access and misuse this information to track or control network nodes, compromising user privacy.
Innovation Solution
A proof-of-presence indicator is generated and validated using a shared secret between the UE and its home PLMN, ensuring that sensitive information is only sent to trusted VPLMNs, thereby minimizing data breaches. This involves the UE generating a proof-of-presence indicator that includes a key, freshness value, and VPLMN identifying information, which is verified by the HPLMN before releasing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If sensitive UE information is communicated to VPLMN for UE-specific operations, then required functionality is maintained, but security risk increases due to potential unauthorized access
Solution Approach 1:
The patent introduces a proof-of-presence indicator as an intermediary mechanism that mediates between the UE and VPLMN. This indicator serves as a trusted verification element that allows the VPLMN to confirm the UE's actual presence without requiring direct access to sensitive UE information, thus maintaining functionality while reducing security risks
Solution Approach 2:
The patent implements preliminary verification by requiring the VPLMN to obtain and validate a proof-of-presence indicator before accessing any sensitive UE information. This preliminary action ensures that only authorized requests from legitimate VPLMNs are processed, preventing unauthorized access while allowing necessary operations to proceed
2Reliability
If proof-of-presence verification is implemented using shared secret, then security against unauthorized access is improved, but complexity of authentication process increases
Solution Approach 1:
The patent applies local quality by implementing verification at specific critical points in the communication flow - specifically when the VPLMN requests sensitive UE information. Rather than adding complexity throughout the entire system, the proof-of-presence verification is localized to the authentication gateway and HPLMN interaction points where it is most needed
3Object-affected harmful factors
If sensitive information is restricted to UE and HPLMN only, then security is improved, but ability to perform operations in VPLMN deteriorates
Solution Approach 1:
The proof-of-presence indicator acts as a mediator that enables VPLMN operations without compromising information security. The indicator contains verification data that allows the HPLMN to authenticate the VPLMN's legitimate need for UE information, thus facilitating operations while maintaining the restriction that sensitive information remains protected
Solution Approach 2:
The patent implements a feedback mechanism where the HPLMN verifies the proof-of-presence indicator and provides feedback to the VPLMN about whether the request is authorized. This feedback loop enables the VPLMN to perform necessary operations when validated, while maintaining security restrictions when validation fails
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, network nodes, computer programs, carrier and user equipment, wherein a proof-of-presence in communications between private land mobile networks (PLMNs) is presented. In an example method performed by a network node in a home public land mobile network (HPLMN) of a user equipment (UE), the network node obtains, from a visited public land mobile network (VPLMN), a proof-of-presence indicator that represents the UE as being present in the VPLMN. The network node verifies whether or not the UE is present in the VPLMN by determining whether or not the proof-of-presence indicator was generated by the UE using a secret shared between the UE and at least the HPLMN. Upon verification of the presence of the UE in the VPLMN, sensitive information can be communicated by the HPLMN to the VPLMN.