Wi-Fi Authentication via Carrier Entitlement Token

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems lack well-developed interworking mechanisms between different technologies, particularly in performing entitlement-based Wi-Fi authentication, which affects privacy and security when accessing carrier Wi-Fi access points.

Innovation Solution

A wireless station performs authentication with a carrier network entitlement server using non-Wi-Fi protocols like LTE or UMTS, obtaining a Wi-Fi service token to authenticate with Wi-Fi access points, thereby leveraging existing cellular authentication procedures and maintaining privacy by not providing permanent identifiers over unprotected Wi-Fi communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional Wi-Fi authentication is used requiring permanent identifiers, then authentication can be performed, but privacy and security are compromised due to exposure of permanent identifiers over unprotected Wi-Fi communication

Engineering Contradiction:
Improveauthentication securityVSAvoidpermanent identifier exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs cellular authentication and obtains a service token before attempting Wi-Fi authentication. This preliminary action ensures that the device is already authenticated and authorized through the secure cellular network, allowing it to access Wi-Fi using the pre-obtained token without exposing permanent identifiers over the potentially insecure Wi-Fi channel.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The service token acts as an intermediary credential that bridges cellular authentication and Wi-Fi access. Instead of directly using permanent identifiers for Wi-Fi authentication, the system uses this intermediate token that was obtained through secure cellular authentication, thereby protecting the permanent identifiers while still enabling Wi-Fi access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If cellular authentication procedures are leveraged for Wi-Fi access, then privacy is improved by avoiding permanent identifier transmission, but additional authentication steps are required

Engineering Contradiction:
Improveprivacy protectionVSAvoidauthentication process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system merges cellular authentication and Wi-Fi authentication into a unified process. By combining the authentication procedures, the device leverages the already-performed cellular authentication to gain Wi-Fi access, reducing the need for separate authentication steps and simplifying the overall process while maintaining privacy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The service token serves multiple functions: it proves cellular authentication, authorizes Wi-Fi access, and can be used for service entitlement verification. This multi-functional credential reduces the need for separate authentication mechanisms and simplifies the overall authentication architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10299123B2Entitlement based Wi-Fi authentication
Publication Date: 2019.05.21 APPLE INC
  • US10299123B2 patent drawing
  • US10299123B2 patent drawing
  • US10299123B2 patent drawing

AI summary

This disclosure relates to techniques for performing Wi-Fi authentication using an entitlement server in a wireless communication system. A wireless station may perform authentication with a carrier network entitlement server, using a protocol other than Wi-Fi. The wireless station may receive a Wi-Fi service token as part of the authentication with the carrier network entitlement server. The wireless station may perform Wi-Fi authentication with a Wi-Fi access point associated with the carrier network using the Wi-Fi service token. After performing Wi-Fi authentication using the Wi-Fi service token, the wireless station may communicate with the carrier network by way of the Wi-Fi access point.