User Identity Layer for Multi-User IoT Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP systems lack the capability to effectively authenticate and identify different users on top of existing subscription authentication, particularly in scenarios where multiple users share the same user equipment (UE).

Innovation Solution

The implementation of a user-centric authentication layer that supports multiple users on the same UE, using a 3GPP User-Identity that is separate from the UE's subscription, allowing users to access customized services and be identified behind a gateway with a 3GPP subscription.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single subscription authentication system is used, then device connectivity is maintained, but user identification and differentiation capabilities are lacking

Engineering Contradiction:
Improveuser identification capabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into two independent layers: subscription authentication (device level) and user authentication (user level). This allows the system to maintain device connectivity through existing subscription mechanisms while adding user identification capability through a separate authentication layer that operates independently, thus improving adaptability without significantly increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to the authentication system by adding user identity as a separate layer above subscription authentication. Instead of modifying the existing subscription layer, it creates a vertical stack where subscription auth handles device connectivity and user auth handles user identification, enabling multi-user support on shared devices without complicating the base subscription system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If multiple users share the same UE, then resource utilization is improved, but user-specific service customization becomes difficult

Engineering Contradiction:
Improvedevice utilization efficiencyVSAvoidservice customization capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent segments user-specific services from device-level connectivity by introducing user identity as a separate authentication layer. This allows multiple users to share the same UE for connectivity purposes while enabling the network to identify and customize services for each user individually through user-specific authentication credentials and policy associations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces user identity as an intermediary between the device and the network services. This intermediary layer enables the network to distinguish between different users sharing the same device and apply appropriate service customizations, parental controls, and policies based on user identity while maintaining efficient device utilization.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If subscription authentication is used, then network access is enabled, but parental controls and user-specific policies cannot be applied

Engineering Contradiction:
Improvenetwork access simplicityVSAvoidpolicy application capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments authentication functionality into subscription authentication for network access and user authentication for policy application. This segmentation maintains the simplicity of subscription-based network access while enabling parental controls and user-specific policies through the additional user authentication layer that operates independently alongside subscription auth.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a user identity dimension to the existing subscription authentication model. This dimensional extension allows the system to maintain simple subscription-based network access while simultaneously enabling sophisticated policy application and parental controls through the perpendicular user authentication layer.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250119735A1Identity layer for IoT devices
Publication Date: 2025.04.10 INTERDIGITAL PATENT HOLDINGS INC
  • US20250119735A1 patent drawing
  • US20250119735A1 patent drawing
  • US20250119735A1 patent drawing

AI summary

A wireless transmit/receive unit (WTRU) may establish a connection with a non-3GPP device. For example, the non-3GPP device may be a smart watch a tablet, a health monitoring device, or an appliance. The connection may be established via a wireless communication protocol, such as WiFi or Bluetooth. The WTRU may establish a connection with a cellular network. The non-3GPP device may lack the capability to connect directly to the cellular network. The WTRU may receive a request from the non-3GPP device for access to the cellular network. The WTRU may perform an authentication procedure with the network using information from the request, such as an identity of the non-3GPP device. After authentication, the WTRU may route data traffic between the non-3GPP device and the cellular network.