Wireless Device Authentication via Encrypted Credential Pre-provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 3GPP communication system faces scalability issues due to the requirement of roaming agreements between wireless networks, and communication links can be broken, preventing authentication credentials from being obtained for wireless devices attempting to attach to foreign networks.
Innovation Solution
A method where the home wireless domain encrypts and sends authentication vectors and security keys to the wireless device, which then decrypts and uses them to authenticate with a foreign wireless domain, bypassing the need for direct roaming agreements and broken link issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If roaming agreements are established between all wireless networks to enable authentication, then authentication capability is improved, but device complexity and system scalability deteriorate due to the need for meshed agreements among all networks
Solution Approach 1:
The patent introduces a trusted authority (home network's MME or HSS) as an intermediary that issues authentication credentials directly to the wireless device. This eliminates the need for direct roaming agreements between foreign networks and home networks, as the trusted authority serves as the central point for credential verification, thereby reducing the complexity of inter-network agreements while maintaining authentication reliability
Solution Approach 2:
The patent creates a universal authentication mechanism where authentication credentials issued by the home network can be used across multiple foreign networks without requiring separate roaming agreements for each network pair. This multi-functional approach allows a single authentication credential to work universally across the 3GPP domain, reducing the overall system complexity
2Speed
If direct communication links are established between foreign MME and home HSS for authentication, then authentication speed is improved, but system reliability deteriorates when communication links are broken or interrupted
Solution Approach 1:
The patent implements preliminary action by having the wireless device obtain and store authentication credentials (including security keys and authentication vectors) in advance from the home network before attempting to attach to foreign networks. This pre-provisioning ensures that authentication can proceed immediately upon entering a foreign network without requiring real-time communication with the home network, thereby maintaining both speed and reliability even when communication links are interrupted
Solution Approach 2:
The patent provides beforehand cushioning by storing multiple authentication vectors and security keys locally in the wireless device's USIM card and memory. These pre-stored credentials act as a cushion or backup that enables authentication to continue even if the primary communication path to the home network is broken, ensuring authentication reliability under adverse conditions
3Reliability
If authentication credentials are stored in the wireless device for foreign network access, then authentication reliability is improved during network disruptions, but security risks increase from potential credential compromise
Solution Approach 1:
The patent applies local quality by implementing different security measures for different types of credentials stored in the device. Sensitive authentication vectors are stored in the secure USIM card hardware, while less sensitive information may be stored in volatile memory. This differentiated approach optimizes both reliability and security by matching the security level of storage to the sensitivity of each credential type
Solution Approach 2:
The patent utilizes parameter changes by transforming authentication credentials into encrypted forms using device-specific keys before storage. The credentials are stored in an encrypted state and only decrypted temporarily during authentication operations. This parameter transformation (from plaintext to encrypted form) maintains authentication reliability while significantly reducing security risks from credential compromise
Data Source
AI summary
A method for obtaining authentication credentials for attaching a wireless device to a foreign wireless domain in a 3rd Generation Partnership Project (3GPP) communication system, which includes: receiving an attach request message from the wireless device; and responsive to the attach request message, authenticating the wireless device and retrieving a set of authentication vectors, wherein the authentication vectors are for authenticating the wireless device to the foreign wireless domain. The method further includes encrypting the set of authentication vectors using a first security key of a home wireless domain of the wireless device. In addition, the method includes encrypting the first security key using a second security key of the foreign wireless domain and sending the encrypted set of authentication vectors and the encrypted first security key to the wireless device.


