Session Establishment Device Authentication via Equipment Identifier Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods in mobile networks, such as those using SIM cards, are vulnerable to unauthorized access due to pre-programmed identifiers, allowing thieves to authenticate and share subscriptions, leading to potential network misuse.
Innovation Solution
Implementing a session establishment device with enhanced authentication mechanisms that verify user equipment identifiers against stored records, including a non-transitory machine-readable medium with instructions to compare received equipment identifiers to stored identifiers, and conditionally reject session establishment if they do not match, as well as allowing service suspension through a web portal server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If pre-programmed identifiers (IMSI, MSISDN) are stored on SIM cards for automatic transmission during session establishment, then authentication convenience is improved, but network security deteriorates due to vulnerability to unauthorized access and subscription sharing
Solution Approach 1:
The patent uses the device identifier (IMEI) as a copy or alternative representation of device identity to verify against the subscriber record. Instead of relying solely on SIM card identifiers that can be cloned, the system copies and verifies the device's inherent hardware identifier to ensure the device itself is authorized, not just the SIM card.
2Reliability
If equipment identifier verification is added to the authentication process, then network security is improved, but authentication complexity increases
Solution Approach 1:
The patent merges the device identifier verification with the existing subscriber authentication process. The equipment identifier (IMEI) is obtained and compared as part of the same session establishment flow, combining device identity verification with subscriber identity verification into a unified authentication mechanism rather than separate processes.
3Reliability
If equipment identifier comparison is performed during session establishment, then unauthorized access prevention is improved, but processing time increases
Solution Approach 1:
The system performs preliminary verification by obtaining and comparing the equipment identifier early in the session establishment process, before full authentication is completed. This allows early rejection of unauthorized devices, preventing wasted processing time on subsequent authentication steps for devices that should be blocked.
Data Source
AI summary
Various exemplary embodiments relate to a method, network node, and non-transitory machine-readable storage medium including one or more of the following: instructions for obtaining, by a session establishment device, a subscriber record associated with a subscriber based on the session establishment device receiving a request message for establishment of a session with respect to a user device, wherein the request message includes a received subscriber identifier associated with the subscriber and a received equipment identifier associated with the user device, and wherein the subscriber record stores a stored subscriber identifier and a stored equipment identifier; instructions for comparing the received equipment identifier to the stored equipment identifier to determine whether the user equipment is associated with the subscriber in the subscriber record; and instructions for conditionally rejecting establishment of the session based on the determination of whether the user equipment is associated with the subscriber in the subscriber record.


