UE Gateway Authentication for Devices Without SIMs or Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Devices without SIMs or digital certificates face challenges in securely connecting to cellular networks, leading to inconsistencies in policy handling and lack of secure authentication/authorization, especially in indoor environments where traditional cellular connectivity is limited.
Innovation Solution
The introduction of a UE Gateway that associates security credentials with devices, enabling them to perform NAS signaling and EAP-TLS protocols, simulating UE functionality to ensure consistent policy handling and secure connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If devices connect to cellular networks without SIMs or digital certificates, then device connectivity is achieved, but security credentials and authentication reliability are compromised
Solution Approach 1:
The patent introduces a gateway device as an intermediary between devices without credentials and the cellular network. The gateway possesses SIM cards or digital certificates and performs authentication on behalf of connected devices, enabling them to access the network without having their own security credentials while maintaining authentication security through the gateway's credentials.
2Adaptability or versatility
If traditional cellular connectivity is used in indoor environments, then network access is provided, but device coverage and connectivity are limited
Solution Approach 1:
The gateway acts as an intermediary that creates a local network infrastructure in indoor environments. It establishes wireless or wired connections between devices and the cellular network, bypassing the need for direct cellular signal penetration into buildings and ensuring stable connections regardless of outdoor signal conditions.
3Ease of operation
If devices without credentials are permitted on the network, then network accessibility is improved, but policy handling consistency deteriorates
Solution Approach 1:
The gateway serves as a policy enforcement intermediary between devices without credentials and the cellular network's policy management system. It translates device connections into credential-based authentication requests, ensuring that policy handling remains consistent with the network's security framework while allowing broad device accessibility.
Solution Approach 2:
The gateway creates virtual representations or copies of device identities that can be authenticated using its own credentials. This allows the network to handle policies consistently as if each device had its own credentials, while in reality the gateway is representing multiple devices using its authenticated session.
4Reliability
If geofencing or additional hardware modifications are implemented, then security is enhanced, but device complexity and cost increase
Solution Approach 1:
The gateway consolidates security functions into a single device rather than requiring security enhancements in each connected device. This intermediary approach provides enhanced security through centralized credential management and authentication while keeping individual devices simple and cost-effective.
Data Source
AI summary
The invention solves the problem of lack of consistency in the policy handling of cellular devices and non-cellular devices. Security credentials that are acceptable to the core network are enabled by the invention to be used for devices that do not have access to such security credentials. This results in consistency in how policy is handled, as it enables the core network to handle policy for all devices, regardless of whether they have access to acceptable security credentials. Acceptable security credentials may be SIM-based credentials or certificate-based credentials, or any acceptable type of security credentials.


