SIM-Based Local Authentication for Wi-Fi Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack the ability for SIM cards to initiate authentication independently and direct it to local entities or devices within a local Wi-Fi network, relying on the mobile cellular network and operator involvement, which is not suitable for all scenarios, especially where network connectivity is unreliable or operator involvement is not desired.

Innovation Solution

A method and system where a local authentication entity, equipped with a subscriber identity module (SIM), sends a request to a network authentication server to authenticate a user terminal, generating and securely storing an authentication key on both the user terminal and the SIM, allowing the SIM to act as an authentication center for other devices within a local network, thereby enabling secure authentication without relying on the mobile network operator.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM-based authentication is linked to the mobile cellular network and HSS, then authentication security is improved, but device complexity and dependency on operator infrastructure increases

Engineering Contradiction:
Improveauthentication securityVSAvoiddependency on operator infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication capability from the centralized HSS and relocates it to the SIM card itself. The SIM card now contains both the subscriber identity module application and the authentication application, enabling it to perform authentication independently without requiring continuous connection to operator infrastructure. This extraction maintains security while reducing dependency on complex operator infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SIM card is designed to perform authentication services autonomously. The authentication application residing on the SIM card can initiate and complete authentication processes locally, generating authentication keys and verifying them without needing to contact the HSS or operator equipment. This self-service capability reduces device complexity by eliminating mandatory infrastructure dependencies.

Inventive Principle:
Principle #25Self-service

2Reliability

If existing authentication solutions like GAA and EAP-SIM are used, then network-based authentication is maintained, but adaptability to local network environments is reduced

Engineering Contradiction:
Improvenetwork-based authenticationVSAvoidlocal network environment adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The SIM card is designed with multi-functionality to operate in different network contexts. It can perform authentication in traditional mobile cellular networks through HSS while also enabling local network authentication independently. The authentication application on the SIM card can initiate authentication requests to local entities or redirect them to the mobile network, providing universal adaptability across different network environments without sacrificing network-based authentication reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If SIM initiates authentication to local entities directly, then adaptability to local networks is improved, but authentication key management complexity increases

Engineering Contradiction:
Improvelocal network authentication capabilityVSAvoidauthentication key management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism for key management where the SIM card generates authentication keys locally but can securely transmit them to authorized entities. The authentication application on the SIM card manages key generation and storage, while the system provides mechanisms for secure key distribution to local authentication entities or the mobile network, reducing the complexity burden on any single component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP1994715B1SIM based authentication
Publication Date: 2014.04.09 BRITISH TELECOM PLC
  • EP1994715B1 patent drawingFigure 1
  • EP1994715B1 patent drawingFigure 2
  • EP1994715B1 patent drawingFigure 3

AI summary

A method of authentication in a communications network, said communications network comprising a network authentication server, a local authentication entity and a user terminal, said local authentication entity comprising a subscriber application and an authentication application, said method comprising the steps of: sending a request from the local authentication entity to the network authentication server to authenticate the user terminal, said request comprising the identity of the user terminal; generating by the network authentication entity an authentication key in response to the request and generating by the subscriber application an identical authentication key; sending the authentication key generated by the network authentication server securely to the user terminal identified by said identity, then storing the authentication key at the user terminal; sending the authentication key generated by the subscriber application securely to the authentication application, then storing the authentication key at the authentication application; and authenticating the user terminal by verifying the authentication key stored at the user terminal with the authentication key stored at the authentication application.