Wireless UE Authorization Using Geographic Access Node Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication networks face challenges in securely authorizing user equipment (UE) for content services, as username and password authentication can be improperly shared, leading to unauthorized access.
Innovation Solution
A system that associates a User Equipment (UE) Identifier with a geographic area and a wireless access node ID, using geographic service boundaries for authorization, ensuring that content services are delivered only to authorized UEs within specific geographic areas.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If username and password authentication is used for content service authorization, then users can access content services, but unauthorized access may occur due to improper sharing of credentials
Solution Approach 1:
The authorization system is segmented into multiple independent components: UE identifier, geographic area identifier, and access node identifier. Each component serves a specific function in the authorization chain, preventing single-point compromise and eliminating the need for shared secret credentials that can be improperly distributed.
Solution Approach 2:
Authorization is made local and context-specific by binding the UE identifier to a particular geographic area and access node. The system evaluates authorization based on the actual location and access point being used, rather than relying on universal credentials. This ensures that even if credentials are compromised, they cannot be used outside their designated geographic and network context.
2Reliability
If geographic area association is implemented for authorization, then unauthorized access is restricted, but system complexity increases due to additional authorization parameters
Solution Approach 1:
The system uses universal, readily available identifiers that already exist in wireless communication infrastructure: UE identifiers (IMSI, IMEI), geographic area identifiers (cell IDs, location data), and access node identifiers. By repurposing these existing identifiers for authorization purposes, the system avoids the complexity of creating and managing new credential systems while achieving enhanced security.
Solution Approach 2:
The authorization system leverages information that is already present and automatically managed by the wireless network infrastructure. The network elements themselves provide the authorization data (UE identifiers, location information, access node identifiers) without requiring external credential management systems, thereby reducing overall system complexity.
Data Source
AI summary
A data communication system stores a User Equipment (UE) Identifier (ID) for a wireless UE in association with a geographic area for the wireless UE. The data communication system wirelessly transfers a wireless access node ID from a wireless access node in the geographic area to the wireless UE. The data communication system receives the UE ID and the wireless access node ID transferred by the wireless UE. The data communication system authorizes the wireless UE for a content service by associating the UE ID with the wireless access node ID based on the geographic area. The content service is delivered to the wireless UE in response to the authorization.


