Secondary Terminal Network Profile via Main Terminal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for accessing a mobile communication network by a secondary terminal without a security module or appropriate authentication data are restrictive, requiring proximity to a main terminal equipped with a security module and limiting independence and security, as they rely on tethering which necessitates the main terminal to remain charged and connected.

Innovation Solution

A method where a secondary terminal obtains a profile for access to a communication network via a main terminal with a security module, using a temporary key and identifier generated by the network, allowing the secondary terminal to access the network independently without relying on the main terminal's proximity or charge status, and ensuring security by limiting key lifetime and avoiding data cloning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If tethering is used to allow a secondary terminal without a security module to access the network via a main terminal, then network access is enabled for the secondary terminal, but the secondary terminal must remain in proximity to the main terminal and the main terminal must stay charged throughout the session

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidoperational constraints
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process into two independent phases: (1) the main terminal authenticates with the network using its security module to obtain a profile, and (2) the secondary terminal uses this profile to authenticate independently. This segmentation allows the secondary terminal to access the network without being physically connected to or dependent on the main terminal's power state, resolving the operational constraints while maintaining network access capability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If tethering is used to share Internet connection from the main terminal to the secondary terminal, then the secondary terminal can access the network, but the main terminal must remain switched on and charged throughout the session

Engineering Contradiction:
Improveconnection sharing capabilityVSAvoidsession continuity
Core Design Contradiction:
Adaptability or versatilityVSDuration of action of moving object

Solution Approach 1:

The patent applies preliminary action by having the main terminal obtain and store an access profile from the network in advance, before the secondary terminal needs to connect. This pre-obtained profile contains all necessary authentication data, allowing the secondary terminal to independently authenticate and maintain network access without requiring the main terminal to remain powered on or charged during the session, thus extending session continuity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If a secondary terminal without authentication data accesses the network via a main terminal, then network access is possible, but security is compromised due to potential cloning of authentication data

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses copying by creating a derived authentication profile for the secondary terminal based on the main terminal's authenticated session. The network generates a temporary profile that is a functional copy of the main terminal's credentials but is specifically tailored for the secondary terminal. This approach enables access capability while maintaining security because the copied credentials are temporary, network-controlled, and cannot be used for cloning or unauthorized access.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11425117B2Method for obtaining a profile for access to a communication network by a secondary terminal via a main terminal
Publication Date: 2022.08.23 ORANGE SA
  • US11425117B2 patent drawing
  • US11425117B2 patent drawing

AI summary

A method for obtaining a profile for access to a communication network by a secondary terminal via a main terminal. The main terminal includes a security element having an authentication key, the authentication key being used by the network and by the main terminal to generate at least one session master key specific to the main terminal. The secondary terminal: provides its identifier to the main terminal; receives from the main terminal a temporary key specific to the secondary terminal, a temporary identifier of the secondary terminal, and an identifier of the network for access to the network. The temporary key is based on the temporary identifier of the secondary terminal and the session master key of the main terminal. The temporary key, the temporary identifier, the identifier of the secondary terminal, and the identifier of the access network are included in an profile for access to the network.