SIM-Based Local Authentication for Wi-Fi Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack the ability for SIM cards to initiate authentication independently and direct it to local entities or devices within a local Wi-Fi network, relying on the mobile cellular network and operator involvement, which is not suitable for all scenarios, especially where network connectivity is unreliable or operator involvement is not desired.
Innovation Solution
A method and system where a local authentication entity, equipped with a subscriber identity module (SIM), sends a request to a network authentication server to authenticate a user terminal, generating and securely storing an authentication key on both the user terminal and the SIM, allowing the SIM to act as an authentication center for other devices within a local network, thereby enabling secure authentication without relying on the mobile network operator.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM-based authentication is linked to the mobile cellular network and HSS, then authentication security is improved, but device complexity and dependency on operator infrastructure increases
Solution Approach 1:
The patent extracts the authentication capability from the centralized HSS and relocates it to the SIM card itself. The SIM card now contains both the subscriber identity module application and the authentication application, enabling it to perform authentication independently without requiring continuous connection to operator infrastructure. This extraction maintains security while reducing dependency on complex operator infrastructure.
Solution Approach 2:
The SIM card is designed to perform authentication services autonomously. The authentication application residing on the SIM card can initiate and complete authentication processes locally, generating authentication keys and verifying them without needing to contact the HSS or operator equipment. This self-service capability reduces device complexity by eliminating mandatory infrastructure dependencies.
2Reliability
If existing authentication solutions like GAA and EAP-SIM are used, then network-based authentication is maintained, but adaptability to local network environments is reduced
Solution Approach 1:
The SIM card is designed with multi-functionality to operate in different network contexts. It can perform authentication in traditional mobile cellular networks through HSS while also enabling local network authentication independently. The authentication application on the SIM card can initiate authentication requests to local entities or redirect them to the mobile network, providing universal adaptability across different network environments without sacrificing network-based authentication reliability.
3Adaptability or versatility
If SIM initiates authentication to local entities directly, then adaptability to local networks is improved, but authentication key management complexity increases
Solution Approach 1:
The patent introduces an intermediary mechanism for key management where the SIM card generates authentication keys locally but can securely transmit them to authorized entities. The authentication application on the SIM card manages key generation and storage, while the system provides mechanisms for secure key distribution to local authentication entities or the mobile network, reducing the complexity burden on any single component.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of authentication in a communications network, said communications network comprising a network authentication server, a local authentication entity and a user terminal, said local authentication entity comprising a subscriber application and an authentication application, said method comprising the steps of: sending a request from the local authentication entity to the network authentication server to authenticate the user terminal, said request comprising the identity of the user terminal; generating by the network authentication entity an authentication key in response to the request and generating by the subscriber application an identical authentication key; sending the authentication key generated by the network authentication server securely to the user terminal identified by said identity, then storing the authentication key at the user terminal; sending the authentication key generated by the subscriber application securely to the authentication application, then storing the authentication key at the authentication application; and authenticating the user terminal by verifying the authentication key stored at the user terminal with the authentication key stored at the authentication application.