Terminal Device Network Locking via OTA Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security mechanisms for terminal devices in WiMAX networks lack effective methods to prevent unauthorized access to other operators' networks and ensure secure locking onto a specific operator's network, which is crucial for operators to retain customers and manage device usage.
Innovation Solution
Implementing a method and system that perform locking-onto-network configuration verification during authentication, using a locking-onto-network character string in the authentication certificate, and enabling/disabling the locking-onto-network function via an Over The Air (OTA) server, ensuring secure access and management of terminal devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If locking-onto-network function is implemented to prevent terminal device from accessing other operators' networks, then operator customer retention is improved, but terminal device flexibility and ease of use deteriorates
Solution Approach 1:
The locking-onto-network function is made dynamic through OTA server control. The locking status can be changed from locked to unlocked based on operational needs, allowing the system to adapt between security and flexibility requirements. The terminal device stores a locking-onto-network flag bit that can be modified remotely.
Solution Approach 2:
The OTA server acts as an intermediary between the operator and the terminal device. It manages the locking-onto-network function by receiving unlocking requests, verifying authentication, and remotely controlling the locking status through the air interface, thus mediating between security requirements and device flexibility.
2Reliability
If locking-onto-network configuration verification is performed during authentication to prevent fake base stations, then network security is improved, but authentication process complexity increases
Solution Approach 1:
The locking-onto-network character string is pre-stored in the terminal device during manufacturing or initial configuration. During authentication, the terminal device retrieves this pre-stored string and compares it with the one from the authentication certificate, avoiding the need for complex real-time verification procedures.
Solution Approach 2:
The locking-onto-network verification function is extracted as a separate, simple comparison operation from the main authentication process. By isolating this verification step, the overall authentication complexity is managed while maintaining security benefits.
3Reliability
If locking-onto-network function is enabled to bind terminal device with operator, then operator customer retention is improved, but device adaptability and versatility deteriorates
Solution Approach 1:
The locking-onto-network function transitions from a static binding mechanism to a dynamic one. The terminal device can be remotely unlocked by the OTA server when needed, allowing it to adapt to different network scenarios while maintaining security during normal operation.
Solution Approach 2:
The locking status parameter can be changed from locked to unlocked through OTA server control. This parameter change allows the terminal device to maintain network binding security during normal use while gaining adaptability when unlocking is required for maintenance or special situations.
Data Source
AI summary
A method, system and terminal device implement locking a terminal device onto a network. This method comprises a procedure of locking onto the network during accessing the network, namely performing locking-onto-network configuration verification in a network accessing authentication process, and if the locking-onto-network configuration verification is successful, allowing for verification for an authentication certificate, or else refusing the terminal device of access to the network. The method, system and terminal device in the present invention perform locking-onto-network configuration verification when performing authentication, and the terminal device and server uniformly configure a locking-onto-network character string, and thus it has a great security. Besides, the present invention also can implement unlocking and locking again after accessing the network via an air interface management in the OTA way, and thus it has high flexibility and applicability, and can satisfy the requirements of 4G networks such as the WiMAX network and LTE network.


