Token-Based IoT Access in 5G Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing subscriptions for a large number of IoT devices connecting to service provider radio access networks is challenging, especially when they are out of range of trusted networks or require internet connectivity without a subscription.

Innovation Solution

IoT devices use a Serial Number and/or MAC address in combination with a token stored on the device to register with a mobile core network, allowing them to access a 5G network without a subscription, by obtaining the token from an IoT vendor and validating it with the vendor's server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IoT devices use subscription identifiers (IMSI/SUPI) to attach to radio access network, then devices can access service provider networks with full functionality, but managing subscriptions for large numbers of devices becomes challenging and complex

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidsubscription management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces temporary access tokens that can be obtained by IoT devices without requiring full subscription management. These tokens are short-lived and can be easily renewed or replaced, avoiding the complexity of managing permanent subscriptions for each device while still enabling network access functionality

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where devices use alternative identifiers (IMEI, MAC address) combined with temporary tokens obtained from authorized vendors. This intermediary system bridges the gap between devices without full subscriptions and the network, reducing the burden of direct subscription management

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If IoT devices obtain temporary access tokens without subscriptions, then subscription management complexity is reduced, but network security and access control become more challenging

Engineering Contradiction:
Improvesubscription management complexityVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic token validation where the network can verify token authenticity, check expiration times, and revoke access as needed. This dynamic approach maintains security by allowing the system to adapt access control decisions based on current device state and network policies, rather than relying on static subscription credentials

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent establishes feedback loops where the network validates tokens against authorized vendor lists and device identifier databases. This feedback mechanism ensures that only legitimately obtained tokens are accepted, maintaining security while enabling simplified access for authorized devices

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If IoT devices use alternative identifiers (IMEI, MAC address) with tokens, then devices can connect without subscriptions, but tracking and managing device access becomes more difficult

Engineering Contradiction:
Improveaccess method flexibilityVSAvoiddevice tracking difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent requires that device identifiers be registered and authorized in advance with the service provider before tokens can be issued. This preliminary registration creates a trusted baseline that simplifies ongoing tracking, as the network already knows which device identifiers are legitimate and should be monitored

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11627465B2Token-based access for internet-of-things devices in wireless wide area networks
Publication Date: 2023.04.11 CISCO TECHNOLOGY INC
  • US11627465B2 patent drawing
  • US11627465B2 patent drawing
  • US11627465B2 patent drawing

AI summary

Presented herein are techniques in which a network device obtains a request from an Internet of Things (IoT) device to access a wireless wide area (WWA) access network. The request includes a token and an identifier associated with the IoT device. The network device transmits a verification request to an IoT vendor associated with the IoT device to determine whether the token and the identifier are valid and obtains an indication from the IoT vendor that the token and the identifier are valid. The network device facilitates connection of the IoT device to the WWA access network based on obtaining the indication that the token and the identifier are valid.