Signed User Location Information via Secure Neighbor Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IEEE 802.11 networks, especially in untrusted access scenarios, there is a lack of interfaces between the home network and the access network for exchanging user-location information, posing challenges for emergency services to obtain network-reported user location information, which is required by regulatory standards.
Innovation Solution
A system and method that generates a public-private key pair to create a cryptographically generated address, uses secure neighbor discovery to obtain a signed user location information from the access network, and sends this information to a 3GPP mobility controller or emergency services through a 3GPP network interface, ensuring secure and trustworthy location reporting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If untrusted access network is used for network expansion, then network coverage is improved, but security and trustworthiness of location information deteriorates
Solution Approach 1:
The patent introduces a trust anchor (home network) as an intermediary that signs location information from untrusted access networks. The home network acts as a mediator that vouches for the authenticity of location data obtained through secure neighbor discovery, allowing untrusted networks to contribute to coverage while maintaining reliability through cryptographic verification.
Solution Approach 2:
The patent changes the security model by transitioning from relying on network operator trust relationships to using cryptographic parameters (digital signatures, public keys). This parameter change enables verification of location information authenticity without requiring trust in the access network operator, resolving the contradiction between using untrusted networks and maintaining reliability.
2Reliability
If no interface exists between home network and untrusted access network, then security boundaries are maintained, but location information exchange capability deteriorates
Solution Approach 1:
The patent extracts the essential function of location information exchange from the traditional trusted interface model. By using secure neighbor discovery and cryptographic signing, the system separates the location information exchange capability from the requirement of a direct trusted interface, allowing exchange over untrusted networks while maintaining security boundary integrity.
Solution Approach 2:
The home network acts as a mediator that provides location information obtained through secure neighbor discovery from untrusted access networks. This intermediary approach allows the home network to maintain security boundaries while still enabling location information exchange by verifying the authenticity of information through cryptographic signatures.
3Reliability
If cryptographic verification is implemented for location information, then trustworthiness is improved, but system complexity deteriorates
Solution Approach 1:
The patent performs preliminary cryptographic setup by establishing public keys and trust anchors in advance. The home network pre-configures verification capabilities, so that during operation, the system only needs to perform signature verification rather than full cryptographic key management. This preliminary action reduces operational complexity while maintaining trustworthiness.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one embodiment, a system, apparatus, and method are described for requesting access authorization from an access network access point (AP) via an access network interface, generating at a processor a public-private key pair (320) to be used to generate a cryptographicaliy generated address (320) upon receiving the access authorization, sending a secure neighbor discovery (SeND) - neighbor solicitation (NS) to the AP via the access network interface after the public-private key pair has been generated (340), receiving a signed user location information (ULI) from the AP in response to the SeND- NS (360), and sending the signed L-l-.l to one of a 3GPP mobility controller or an emergency service via a 3GPP network interface (380). Related systems, apparatuses, and methods are also described.