User Identity Layer for Multi-User IoT Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP systems lack the capability to effectively authenticate and identify different users on top of existing subscription authentication, particularly in scenarios where multiple users share the same user equipment (UE).
Innovation Solution
The implementation of a user-centric authentication layer that supports multiple users on the same UE, using a 3GPP User-Identity that is separate from the UE's subscription, allowing users to access customized services and be identified behind a gateway with a 3GPP subscription.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single subscription authentication system is used, then device connectivity is maintained, but user identification and differentiation capabilities are lacking
Solution Approach 1:
The patent segments the authentication system into two independent layers: subscription authentication (device level) and user authentication (user level). This allows the system to maintain device connectivity through existing subscription mechanisms while adding user identification capability through a separate authentication layer that operates independently, thus improving adaptability without significantly increasing overall system complexity.
Solution Approach 2:
The patent introduces a new dimension to the authentication system by adding user identity as a separate layer above subscription authentication. Instead of modifying the existing subscription layer, it creates a vertical stack where subscription auth handles device connectivity and user auth handles user identification, enabling multi-user support on shared devices without complicating the base subscription system.
2Productivity
If multiple users share the same UE, then resource utilization is improved, but user-specific service customization becomes difficult
Solution Approach 1:
The patent segments user-specific services from device-level connectivity by introducing user identity as a separate authentication layer. This allows multiple users to share the same UE for connectivity purposes while enabling the network to identify and customize services for each user individually through user-specific authentication credentials and policy associations.
Solution Approach 2:
The patent introduces user identity as an intermediary between the device and the network services. This intermediary layer enables the network to distinguish between different users sharing the same device and apply appropriate service customizations, parental controls, and policies based on user identity while maintaining efficient device utilization.
3Ease of operation
If subscription authentication is used, then network access is enabled, but parental controls and user-specific policies cannot be applied
Solution Approach 1:
The patent segments authentication functionality into subscription authentication for network access and user authentication for policy application. This segmentation maintains the simplicity of subscription-based network access while enabling parental controls and user-specific policies through the additional user authentication layer that operates independently alongside subscription auth.
Solution Approach 2:
The patent adds a user identity dimension to the existing subscription authentication model. This dimensional extension allows the system to maintain simple subscription-based network access while simultaneously enabling sophisticated policy application and parental controls through the perpendicular user authentication layer.
Data Source
AI summary
A wireless transmit/receive unit (WTRU) may establish a connection with a non-3GPP device. For example, the non-3GPP device may be a smart watch a tablet, a health monitoring device, or an appliance. The connection may be established via a wireless communication protocol, such as WiFi or Bluetooth. The WTRU may establish a connection with a cellular network. The non-3GPP device may lack the capability to connect directly to the cellular network. The WTRU may receive a request from the non-3GPP device for access to the cellular network. The WTRU may perform an authentication procedure with the network using information from the request, such as an identity of the non-3GPP device. After authentication, the WTRU may route data traffic between the non-3GPP device and the cellular network.


