Secondary Terminal Network Profile via Main Terminal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for accessing a mobile communication network by a secondary terminal without a security module or appropriate authentication data are restrictive, requiring proximity to a main terminal equipped with a security module and limiting independence and security, as they rely on tethering which necessitates the main terminal to remain charged and connected.
Innovation Solution
A method where a secondary terminal obtains a profile for access to a communication network via a main terminal with a security module, using a temporary key and identifier generated by the network, allowing the secondary terminal to access the network independently without relying on the main terminal's proximity or charge status, and ensuring security by limiting key lifetime and avoiding data cloning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If tethering is used to allow a secondary terminal without a security module to access the network via a main terminal, then network access is enabled for the secondary terminal, but the secondary terminal must remain in proximity to the main terminal and the main terminal must stay charged throughout the session
Solution Approach 1:
The patent segments the authentication process into two independent phases: (1) the main terminal authenticates with the network using its security module to obtain a profile, and (2) the secondary terminal uses this profile to authenticate independently. This segmentation allows the secondary terminal to access the network without being physically connected to or dependent on the main terminal's power state, resolving the operational constraints while maintaining network access capability.
2Adaptability or versatility
If tethering is used to share Internet connection from the main terminal to the secondary terminal, then the secondary terminal can access the network, but the main terminal must remain switched on and charged throughout the session
Solution Approach 1:
The patent applies preliminary action by having the main terminal obtain and store an access profile from the network in advance, before the secondary terminal needs to connect. This pre-obtained profile contains all necessary authentication data, allowing the secondary terminal to independently authenticate and maintain network access without requiring the main terminal to remain powered on or charged during the session, thus extending session continuity.
3Adaptability or versatility
If a secondary terminal without authentication data accesses the network via a main terminal, then network access is possible, but security is compromised due to potential cloning of authentication data
Solution Approach 1:
The patent uses copying by creating a derived authentication profile for the secondary terminal based on the main terminal's authenticated session. The network generates a temporary profile that is a functional copy of the main terminal's credentials but is specifically tailored for the secondary terminal. This approach enables access capability while maintaining security because the copied credentials are temporary, network-controlled, and cannot be used for cloning or unauthorized access.
Data Source
AI summary
A method for obtaining a profile for access to a communication network by a secondary terminal via a main terminal. The main terminal includes a security element having an authentication key, the authentication key being used by the network and by the main terminal to generate at least one session master key specific to the main terminal. The secondary terminal: provides its identifier to the main terminal; receives from the main terminal a temporary key specific to the secondary terminal, a temporary identifier of the secondary terminal, and an identifier of the network for access to the network. The temporary key is based on the temporary identifier of the secondary terminal and the session master key of the main terminal. The temporary key, the temporary identifier, the identifier of the secondary terminal, and the identifier of the access network are included in an profile for access to the network.

