SUPL Authentication Across Heterogeneous Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure User Plane Location (SUPL) systems face challenges in authentication across various access networks, particularly due to differences in security schemes between 3GPP, 3GPP2, WiMAX, and Wi-Fi networks, leading to limitations in functionality, especially in indoor or poor cellular conditions.

Innovation Solution

The implementation of a system that enables mutual authentication in SUPL systems independently of the access network, using methods such as Generic Bootstrapping Architecture (GBA)-based authentication, SUPL Encryption Key (SEK)-based authentication, Certificate-based authentication, Alternative Client Authentication (ACA), and Transport Layer Security (TLS) encryption/decryption logic, allowing support for multiple networks like 3GPP, 3GPP2, WiMAX, and Wi-Fi.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access network-specific authentication schemes are used in SUPL systems, then security can be maintained for each specific network type, but functionality and adaptability are limited across different network types

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality across networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication framework that works across multiple access networks (3GPP, 3GPP2, WiMAX, Wi-Fi) by defining network-independent authentication methods. The SUPL authentication mechanism is designed to be access network agnostic, allowing the same authentication procedures to function regardless of which network type is being used, thereby resolving the contradiction between maintaining security and achieving cross-network functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication process is segmented into distinct phases: network selection, authentication method negotiation, and actual authentication. This segmentation allows the system to first determine which network is being accessed, then select the appropriate authentication method from a set of supported methods, and finally perform the authentication. This structured approach enables both network-specific security requirements and cross-network functionality to be satisfied.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple authentication methods are supported for different networks, then adaptability improves, but device complexity increases

Engineering Contradiction:
Improvesupport for multiple networksVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically selects the appropriate authentication method based on the current access network type and the capabilities of both the SET and SLP. Rather than implementing all authentication methods simultaneously in a static manner, the system negotiates and activates only the methods relevant to the current network context, reducing the effective complexity while maintaining support for multiple networks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an authentication method negotiation mechanism that acts as an intermediary between the SET and SLP. This negotiation process determines which authentication methods are supported by both parties and selects the appropriate method based on the access network type. This intermediary layer simplifies the overall system complexity by managing the complexity of multiple authentication methods through a standardized negotiation protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network-specific authentication is implemented, then authentication reliability for each network is maintained, but ease of operation across different networks deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidseamless authentication across networks
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system changes the parameter of authentication method selection based on the access network type. Rather than using fixed network-specific authentication procedures, the system dynamically adjusts which authentication method is used according to the detected network type (3GPP, 3GPP2, WiMAX, or Wi-Fi). This parameter change approach maintains authentication reliability for each network while providing seamless operation from the user perspective, as the selection process is transparent and automated.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2636203B1Authentication in secure user plane location (SUPL) systems
Publication Date: 2020.10.21 QUALCOMM INC
  • EP2636203B1 patent drawingFigure 1
  • EP2636203B1 patent drawingFigure 2
  • EP2636203B1 patent drawingFigure 3

AI summary

A particular method includes storing, at a mobile device, at least one security credential that is specific to the mobile device. The method also includes transmitting the at least one security credential to a secure user plane location (SUPL) location platform (SLP) to authenticate the mobile device as associated with a SUPL user based on a comparison of the device identifier to stored device identifier. The disclosed techniques may enable a SUPL server and a SUPL enabled terminal SET to negotiate which of a plurality of authentication methods is to be used.