Session Establishment Device Authentication via Equipment Identifier Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods in mobile networks, such as those using SIM cards, are vulnerable to unauthorized access due to pre-programmed identifiers, allowing thieves to authenticate and share subscriptions, leading to potential network misuse.

Innovation Solution

Implementing a session establishment device with enhanced authentication mechanisms that verify user equipment identifiers against stored records, including a non-transitory machine-readable medium with instructions to compare received equipment identifiers to stored identifiers, and conditionally reject session establishment if they do not match, as well as allowing service suspension through a web portal server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If pre-programmed identifiers (IMSI, MSISDN) are stored on SIM cards for automatic transmission during session establishment, then authentication convenience is improved, but network security deteriorates due to vulnerability to unauthorized access and subscription sharing

Engineering Contradiction:
Improveauthentication convenienceVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent uses the device identifier (IMEI) as a copy or alternative representation of device identity to verify against the subscriber record. Instead of relying solely on SIM card identifiers that can be cloned, the system copies and verifies the device's inherent hardware identifier to ensure the device itself is authorized, not just the SIM card.

Inventive Principle:
Principle #26Copying

2Reliability

If equipment identifier verification is added to the authentication process, then network security is improved, but authentication complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the device identifier verification with the existing subscriber authentication process. The equipment identifier (IMEI) is obtained and compared as part of the same session establishment flow, combining device identity verification with subscriber identity verification into a unified authentication mechanism rather than separate processes.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If equipment identifier comparison is performed during session establishment, then unauthorized access prevention is improved, but processing time increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsession establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary verification by obtaining and comparing the equipment identifier early in the session establishment process, before full authentication is completed. This allows early rejection of unauthorized devices, preventing wasted processing time on subsequent authentication steps for devices that should be blocked.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10021563B2Enhanced authentication for provision of mobile services
Publication Date: 2018.07.10 ALCATEL LUCENT CANADA INC
  • US10021563B2 patent drawing
  • US10021563B2 patent drawing
  • US10021563B2 patent drawing

AI summary

Various exemplary embodiments relate to a method, network node, and non-transitory machine-readable storage medium including one or more of the following: instructions for obtaining, by a session establishment device, a subscriber record associated with a subscriber based on the session establishment device receiving a request message for establishment of a session with respect to a user device, wherein the request message includes a received subscriber identifier associated with the subscriber and a received equipment identifier associated with the user device, and wherein the subscriber record stores a stored subscriber identifier and a stored equipment identifier; instructions for comparing the received equipment identifier to the stored equipment identifier to determine whether the user equipment is associated with the subscriber in the subscriber record; and instructions for conditionally rejecting establishment of the session based on the determination of whether the user equipment is associated with the subscriber in the subscriber record.