Virtual IMSI Authentication for Alternate Access Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile networks face challenges in efficiently managing data communications due to high demand from wireless devices, leading to delayed or lost data transmissions, especially when users transition between cellular and alternate access networks like WLAN, which often lack SIM-based authentication methods.

Innovation Solution

The implementation of non-mobile authentication methods using a wireless access gateway (WAG) that emulates SIM-based authentication by obtaining a virtual International Mobile Subscriber Identity (IMSI) from a subscriber database, allowing seamless connectivity and unified policy and charging control across different access networks without requiring traditional SIM-based authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional SIM-based authentication is used in mobile networks, then network security and subscriber management are ensured, but wireless devices cannot seamlessly access alternate access networks like WLAN that lack SIM-based authentication

Engineering Contradiction:
Improvenetwork access compatibilityVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a copy of the mobile network authentication mechanism by introducing a Virtual IMSI (V-IMSI) that replicates the functionality of a traditional SIM card IMSI. The V-IMSI allows wireless devices to authenticate on alternate access networks like WLAN without requiring actual SIM cards, thereby copying the essential authentication capability while adapting it to non-mobile networks. This resolves the contradiction by enabling broad network compatibility while maintaining authentication reliability through the virtual identity system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the wireless device and the mobile network gateway. This server mediates the authentication process by generating and managing V-IMSI values, allowing devices without SIM cards to authenticate seamlessly. The intermediary translates between the alternate access network's authentication capabilities and the mobile network's requirements, resolving the incompatibility between different network types while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If wireless devices frequently transition between cellular and alternate access networks, then network flexibility and user mobility are improved, but IP address preservation and session continuity become problematic

Engineering Contradiction:
Improvenetwork transition flexibilityVSAvoidsession establishment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs preliminary authentication and IP address assignment actions before the wireless device actually transitions between networks. By pre-establishing the V-IMSI identity and obtaining IP addresses in advance through the authentication server, the system prepares the session parameters ahead of time. This preliminary action ensures that when network transitions occur, the device can seamlessly maintain its IP address and session continuity without time-consuming re-authentication processes.

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If mobile networks handle increasing data traffic demand, then service coverage is expanded, but network resources become strained leading to delayed or lost data communications

Engineering Contradiction:
Improvedata traffic capacityVSAvoiddata transmission efficiency
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The patent segments the authentication and session management functions from the core mobile network infrastructure by introducing a separate authentication server that handles V-IMSI generation and management. This segmentation offloads authentication processing from the mobile network gateway, reducing the processing burden on core network elements. By dividing the system into separate functional components, the patent enables the mobile network to handle increased data traffic capacity without compromising transmission efficiency, as the segmented architecture distributes the processing load more effectively.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10021566B2Non-mobile authentication for mobile network gateway connectivity
Publication Date: 2018.07.10 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10021566B2 patent drawing
  • US10021566B2 patent drawing
  • US10021566B2 patent drawing

AI summary

In general, techniques are described for emulating mobile authentication methods to establish authenticated connectivity between a mobile service provider gateway and a wireless device attached to an alternate access network. For example, a system operating according to the described techniques includes a mobile service provider network, an alternate access network having an access gateway, and an authentication server of the mobile service provider network that receives a network access request. A subscriber database responds to the network access request with virtual mobility information, wherein the network access request does not include an International Mobile Subscriber Identity (IMSI), and wherein the virtual mobility information comprises a virtual IMSI. The access gateway uses the virtual mobility information to signal a mobile network gateway of the mobile service provider network to establish a service session for the wireless device over the alternate access network that is anchored by the mobile network gateway.