Public Wireless Network Authentication via Mobile Card Module Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current public wireless network authentication methods are not simple, secure, or effective in identifying users and tracing data activity, with existing solutions burdening mobile networks and lacking permanent user credential binding, leading to inefficiencies in implementation and maintenance costs.

Innovation Solution

A method that retrieves a unique code from a mobile cellular network card module to generate and store wireless credentials, binding them permanently to the ICCID, allowing automatic authentication and registration, and using a database to manage user identity data and credentials, ensuring secure and efficient user access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1X authentication is used, then authentication security is improved, but device complexity increases due to requiring client software installation

Engineering Contradiction:
Improveauthentication securityVSAvoidclient software requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a portal server as an intermediary between the user equipment and the network authentication system. The portal server handles credential verification and user identification through a web-based interface, eliminating the need for complex client software while maintaining authentication security through the portal-mediated authentication process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If UAM authentication is used, then ease of operation is improved by using web browser, but user identification reliability deteriorates due to lack of permanent credential binding

Engineering Contradiction:
Improveweb browser authenticationVSAvoiduser identification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary user registration and credential binding before actual authentication. During registration, user identifiers (such as mobile device identifiers) are bound to authentication credentials in advance. This preliminary binding ensures that when web browser authentication occurs, the credentials are permanently linked to specific users, enabling reliable user identification and tracing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where user identification information is collected during authentication and used to trace data activity. The portal server receives authentication credentials, verifies them against bound user identifiers, and provides feedback about successful authentication along with user identification data that enables ongoing activity tracing

Inventive Principle:
Principle #23Feedback

3Loss of information

If manual credential entry is required, then user identification is obtained, but implementation time and maintenance costs increase

Engineering Contradiction:
Improveuser identity data collectionVSAvoidimplementation and maintenance time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent enables self-service registration where user equipment automatically provides its own identification information (such as mobile device identifiers) during the registration process. Users simply need to access the portal, and the system automatically binds the device identifier to credentials without requiring manual data entry or extensive administrative intervention, thereby reducing implementation and maintenance time

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3289788B1Method and system for authenticating users in public wireless networks
Publication Date: 2023.09.13 TELECOM ITALIA SPA
  • EP3289788B1 patent drawingFigure 1~4
  • EP3289788B1 patent drawingFigure 2

AI summary

A method for authenticating a user of a user equipment (100) provided with a mobile cellular network card module (130) in a public wireless network (120) is provided. The method comprises: - during an authentication procedure following an attempt (205) by the user to access the public wireless network (120) with the user equipment (100) for availing of services provided by the public wireless network (120): - retrieving (250) from the mobile cellular network card module (130) a code that uniquely identifies such mobile cellular network card module (130); - retrieving (250) from a database (160) wireless credentials of the user associated with said retrieved code that uniquely identifies such mobile cellular network card module (130); - providing said retrieved wireless credentials of the user (260) to the public wireless network (120); - granting (270, 280, 290) the user access to the public wireless network (120) conditioned to the correctness of the provided wireless credentials (250; 260).