Wireless Device Authentication via Distributed Ledger
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP mobile networks are not designed for massive onboarding of new subscribers, particularly in the context of Machine to Machine (M2M) communication and Internet of Things (IoT), which incurs additional costs due to the need for IMSI procurement and integration in wireless devices.
Innovation Solution
A method allowing wireless devices to temporarily attach to a communication network without IMSIs, where behavior analysis determines ownership and authentication, using a distributed ledger to store device information and behavior patterns, enabling authentication and subscription management without hardcoded credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If wireless devices use traditional IMSI-based authentication, then network security and authentication reliability are maintained, but device costs and onboarding complexity increase due to SIM card procurement and integration
Solution Approach 1:
The patent extracts the authentication credentials (IMSI and encryption key) from the traditional SIM card hardware and relocates them to a distributed ledger system. This allows devices to authenticate without physical SIM cards, eliminating the need for SIM procurement and integration while maintaining cryptographic security through blockchain-based credential verification
Solution Approach 2:
The distributed ledger acts as an intermediary between the network operator and wireless devices, replacing the traditional SIM card as the credential storage medium. The ledger stores authentication credentials and enables verification without requiring direct hardware integration between operator and device, simplifying onboarding while maintaining security
2Reliability
If wireless devices store IMSI and encryption key in hardware modules, then authentication security is maintained, but manufacturing costs and integration complexity increase
Solution Approach 1:
The patent removes the requirement for hardware-based credential storage by extracting authentication functionality from the SIM card hardware and implementing it in software on the distributed ledger. This eliminates the need for secure element integration in devices, significantly simplifying manufacturing while maintaining cryptographic security through ledger-based credential management
Solution Approach 2:
The authentication credentials are copied from the operator's core network to the distributed ledger, which then serves as the authoritative source for verification. This eliminates the need for each device to have its own hardware copy of credentials, reducing manufacturing complexity while maintaining security through decentralized verification
3Reliability
If traditional challenge-based authentication is used, then individual device authentication is secure, but massive device onboarding efficiency decreases due to feedback loops and human interaction requirements
Solution Approach 1:
The patent performs preliminary actions by pre-configuring the distributed ledger with authentication credentials and device information before mass deployment. Enterprise customers can register their devices in advance on the ledger, enabling automated onboarding without manual feedback loops when devices are deployed, thus maintaining security while dramatically increasing onboarding speed
Solution Approach 2:
The distributed ledger enables self-service authentication where devices can automatically register and authenticate themselves without human intervention. The ledger autonomously verifies credentials and provisions services, eliminating the manual feedback loops between operators and enterprise customers that slow down traditional mass onboarding processes
Data Source
AI summary
According to an aspect, there is provided a method of operating an analysis node. The method comprises receiving, from a network node in a first communication network to which a first wireless device is attached, behaviour information relating to the behaviour of the first wireless device with respect to the first communication network during a time period following attachment of the first wireless device to the first communication network; analysing the received behaviour information with reference to predetermined behaviour information for wireless devices owned by one or more third parties to determine whether the first wireless device is owned by one of the third parties; and sending an indication of whether the first wireless device is to be authenticated in the first communication network, wherein the indication is based on whether the first wireless device is determined to be owned by one of the third parties.


