USIM-Based Wireless Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless authentication methods for mobile terminals in wireless telecommunications networks face security issues, particularly with public Wi-Fi networks, where password-based authentication is insecure and VPN solutions are cumbersome and not scalable, while existing 3G network connections are limited by high latency and cost.

Innovation Solution

A method for secure authentication using a USIM card with a 3GPP-compatible modem, emulating a PC/SC driver via standard application ports, enabling transparent and secure EAP-SIM authentication without the need for proprietary readers or manual configuration, ensuring compatibility with existing and future 3GPP modems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based authentication is used for public Wi-Fi access, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with an electronic/usim card-based authentication system. The usim card stores cryptographic credentials and automatically performs authentication with the network, eliminating the need for users to manually enter passwords while providing stronger security through hardware-based credential storage and cryptographic protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If VPN tunneling is implemented for secure data transfer, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from the application layer (VPN) and moves it to the network access layer through USIM card-based authentication. This separates the security mechanism from the data transfer protocol, providing security at the network connection level without requiring complex VPN configurations, routing tables, or encryption management at the device level.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If proprietary PC/SC card readers are used for authentication, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent makes the USIM card universally applicable for both mobile network access and Wi-Fi authentication. The same USIM card that users already possess for their mobile phone service can be used for wireless network authentication, eliminating the need for separate proprietary card readers or additional authentication devices. This is achieved through standardization of the authentication interface and protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If manual VPN configuration is required, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the USIM card automatically performs the authentication process with the wireless network. The card contains all necessary credentials and cryptographic material, and the authentication protocol is executed automatically without requiring users to manually configure VPN settings, enter account information, or manage security parameters. The system handles the entire authentication sequence autonomously.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2341688B1Method for securely authenticating a terminal roaming in a wireless network.
Publication Date: 2018.10.10 SOC FR DU RADIOTELEPHONE SFR
  • EP2341688B1 patent drawingFigure 1~3
  • EP2341688B1 patent drawingFigure 4~5
  • EP2341688B1 patent drawingFigure 6~7

AI summary

The method involves initiating a dialog session between a terminal (20) and a universal subscriber identity module (SIM) card (24) along a secured communication protocol with command/responses comprising AT+ code division multiple accessSIM, during authenticating procedure. The command and responses are produced and emitted by the terminal and the SIM card. The terminal is connected to a mobile telecommunication modem (22) via universal serial busconnection. An independent claim is also included for a terminal comprising a mobile telecommunication modem.