Terminal Device Network Locking via OTA Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security mechanisms for terminal devices in WiMAX networks lack effective methods to prevent unauthorized access to other operators' networks and ensure secure locking onto a specific operator's network, which is crucial for operators to retain customers and manage device usage.

Innovation Solution

Implementing a method and system that perform locking-onto-network configuration verification during authentication, using a locking-onto-network character string in the authentication certificate, and enabling/disabling the locking-onto-network function via an Over The Air (OTA) server, ensuring secure access and management of terminal devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If locking-onto-network function is implemented to prevent terminal device from accessing other operators' networks, then operator customer retention is improved, but terminal device flexibility and ease of use deteriorates

Engineering Contradiction:
Improvenetwork access securityVSAvoiddevice flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The locking-onto-network function is made dynamic through OTA server control. The locking status can be changed from locked to unlocked based on operational needs, allowing the system to adapt between security and flexibility requirements. The terminal device stores a locking-onto-network flag bit that can be modified remotely.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The OTA server acts as an intermediary between the operator and the terminal device. It manages the locking-onto-network function by receiving unlocking requests, verifying authentication, and remotely controlling the locking status through the air interface, thus mediating between security requirements and device flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If locking-onto-network configuration verification is performed during authentication to prevent fake base stations, then network security is improved, but authentication process complexity increases

Engineering Contradiction:
Improvenetwork access securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The locking-onto-network character string is pre-stored in the terminal device during manufacturing or initial configuration. During authentication, the terminal device retrieves this pre-stored string and compares it with the one from the authentication certificate, avoiding the need for complex real-time verification procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The locking-onto-network verification function is extracted as a separate, simple comparison operation from the main authentication process. By isolating this verification step, the overall authentication complexity is managed while maintaining security benefits.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If locking-onto-network function is enabled to bind terminal device with operator, then operator customer retention is improved, but device adaptability and versatility deteriorates

Engineering Contradiction:
Improvenetwork binding securityVSAvoidnetwork compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The locking-onto-network function transitions from a static binding mechanism to a dynamic one. The terminal device can be remotely unlocked by the OTA server when needed, allowing it to adapt to different network scenarios while maintaining security during normal operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The locking status parameter can be changed from locked to unlocked through OTA server control. This parameter change allows the terminal device to maintain network binding security during normal use while gaining adaptability when unlocking is required for maintenance or special situations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8732458B2Method, system and terminal device for realizing locking network by terminal device
Publication Date: 2014.05.20 ZTE CORP
  • US8732458B2 patent drawing
  • US8732458B2 patent drawing
  • US8732458B2 patent drawing

AI summary

A method, system and terminal device implement locking a terminal device onto a network. This method comprises a procedure of locking onto the network during accessing the network, namely performing locking-onto-network configuration verification in a network accessing authentication process, and if the locking-onto-network configuration verification is successful, allowing for verification for an authentication certificate, or else refusing the terminal device of access to the network. The method, system and terminal device in the present invention perform locking-onto-network configuration verification when performing authentication, and the terminal device and server uniformly configure a locking-onto-network character string, and thus it has a great security. Besides, the present invention also can implement unlocking and locking again after accessing the network via an air interface management in the OTA way, and thus it has high flexibility and applicability, and can satisfy the requirements of 4G networks such as the WiMAX network and LTE network.