Cross-Network Authentication via SIM Result Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods face challenges in seamlessly authenticating users when roaming between different wireless telecommunications networks, such as 3G/Wi-Fi or 4G/WiMAX, due to difficulties in interfacing with SIM cards and implementing SIM-based authentication protocols across various operating systems, leading to costly and time-consuming modifications.

Innovation Solution

The solution leverages the authentication result from a first network to bypass the A3 algorithm in the SIM card, using a public API to perform authentication in a second network, allowing the user credential to be transferred and utilized for access, with a client on the mobile device or an authentication gateway facilitating this process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If SIM-based authentication protocol (EAP-SIM/EAP-AKA) is implemented in Wi-Fi or WiMAX networks, then user authentication across different networks is enabled, but operating systems must be specifically modified for each mobile device which is expensive and time-consuming

Engineering Contradiction:
Improveauthentication compatibility across networksVSAvoidoperating system modification cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that bridges the mobile device and Wi-Fi/WiMAX networks. Instead of modifying operating systems to implement EAP-SIM/EAP-AKA directly, the system uses an intermediate authentication server that handles the SIM card verification and translates it into network-compatible authentication formats. This intermediary layer eliminates the need for OS-specific modifications while maintaining cross-network authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual representation of the SIM card authentication process that can be replicated across different operating systems without actual SIM card access. By copying the authentication logic and results from the mobile network to the Wi-Fi/WiMAX network through server-mediated communication, the system achieves authentication compatibility without modifying each device's operating system.

Inventive Principle:
Principle #26Copying

2Ease of operation

If application layer attempts to interface with SIM card for authentication, then authentication can be performed, but security sensitivity prevents operating systems from allowing direct application access to SIM card

Engineering Contradiction:
Improveauthentication implementationVSAvoidsubscriber data security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent moves the authentication process from the application layer to a different dimensional space - the network layer. Instead of applications directly accessing SIM cards (horizontal access within the same layer), the system establishes a vertical communication channel through authentication servers that operate at the network layer. This dimensional shift allows authentication to proceed without compromising SIM card security, as the application never directly interfaces with the SIM card.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent segments the authentication process into distinct components: SIM card verification, authentication result generation, and network access authorization. The SIM card interface is isolated and segmented from the application layer, with only the authentication result (not the SIM card itself) being transmitted to the network. This segmentation maintains security by preventing direct application-SIM card communication while enabling authentication functionality.

Inventive Principle:
Principle #1Segmentation

3Reliability

If standard SIM authentication procedure is used in roaming scenarios, then network security is maintained, but seamless roaming between 3G/4G and Wi-Fi/WiMAX networks cannot be achieved

Engineering Contradiction:
Improvenetwork securityVSAvoidroaming capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication mechanism that functions across multiple network types (3G, 4G, Wi-Fi, WiMAX) without requiring network-specific modifications. The authentication server acts as a universal translator that accepts SIM card authentication results and converts them into appropriate formats for different network types. This multi-functional approach maintains the security of standard SIM authentication while enabling seamless roaming across diverse network infrastructures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9716999B2Method of and system for utilizing a first network authentication result for a second network
Publication Date: 2017.07.25 SYNIVERSE COMM LLC
  • US9716999B2 patent drawing
  • US9716999B2 patent drawing
  • US9716999B2 patent drawing

AI summary

A method and system for completing the authentication process in a second communication network (such as Wi-Fi or WiMAX) utilizes a user credential of a first communication network, such as GSM, UMTS, CDMA, or LTE. Preferably, the user credential is a SIM card, a USIM card, a R-UIM card, or a functionally similar component. The system includes a client and an authentication platform that retrieves Service State information of the user credential in the first communication network and passes the information to the authentication platform of the second communication network. The client is granted access to the second communication network after the authentication platform validates the client's service and subscription status with the first communication network.