Unified Data Management Set for Private Mobile Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing telecommunications systems face challenges in ensuring seamless device authentication and service authorization in private mobile networks, particularly in maintaining synchronization between operator networks and vertical networks, while minimizing traffic and procedures in the operator network once devices are connected to vertical networks.

Innovation Solution

The implementation of a Unified Data Management (UDM) set, where UDM instances from both operator and vertical networks are brought into a single UDM set, facilitates device authentication and service authorization. This setup allows for regular synchronization of UDM instances, ensures that vertical networks are aware of device authentication status, and reduces the need for repeated procedures in the operator network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device authentication is performed in the operator network using UDM, then security is improved, but network traffic and procedures in the operator network increase

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork traffic
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The UDM set is segmented into multiple UDM instances, where the first UDM instance handles authentication for the private network while the second UDM instance handles authentication for the operator network. This segmentation allows authentication to be distributed across specialized instances, improving security for the private network while managing operator network traffic efficiently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first UDM instance acts as an intermediary between the private network and the operator network authentication system. It receives authentication requests from the private network, performs authentication using credentials from the second UDM instance, and returns authentication results. This intermediary role enables secure private network authentication while reducing direct traffic in the operator network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a UDM set with multiple UDM instances is implemented, then service authorization and authentication across networks is improved, but device complexity increases

Engineering Contradiction:
Improveservice authorizationVSAvoidUDM set complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Each UDM instance in the set is designed to be universal and multi-functional, capable of performing authentication and authorization functions for different network types. The first UDM instance serves the private network while the second serves the operator network, but both instances use the same fundamental UDM architecture and protocols. This universality enables flexible service authorization across networks while avoiding the need for completely separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The UDM set uses a copying approach where the second UDM instance maintains a copy of authentication credentials that are also present in the first UDM instance. This copying mechanism allows the first UDM instance to perform authentication for the private network independently, without requiring complex real-time synchronization with the operator network, thereby reducing overall system complexity while maintaining versatility.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12207354B2Facilitating services for devices in private mobile networks based on device authentications in an operator network
Publication Date: 2025.01.21 CISCO TECHNOLOGY INC
  • US12207354B2 patent drawing
  • US12207354B2 patent drawing
  • US12207354B2 patent drawing

AI summary

In one illustrative example, a unified data management (UDM) of a mobile network is established in a UDM set with a plurality of private network UDMs instances of a plurality of private mobile networks. The UDM of the mobile network provides access to a plurality of subscription profiles associated with a plurality of subscribers of the mobile network, and each private network UDM instance provides access to a subset of the subscription profiles associated with a subset of the subscribers in the private mobile network. The UDM of the mobile network operates to communicate, in an authentication procedure, authentication data for authentication of a user equipment (UE) in the mobile network. After the authentication of the UE in the mobile network, the UDM operates to push authentication status information of the UE to the private network UDM instance of the private mobile network.