Wireless Network Privacy Through Authenticated Mobility to Non-Public Cells
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication networks face privacy and security threats due to the transmission of network identifiers, such as PLMN IDs and CAG IDs, which can reveal sensitive network associations, particularly in non-public networks like SNPNs and PNiNPNs, making it challenging to enable access while concealing these associations from unauthorized parties.
Innovation Solution
A method involving secured NAS signaling and mobility procedures is employed to authenticate wireless devices for access to non-public networks, where network nodes control mobility commands to conceal the association with the second network from unauthorized devices, using identifiers like PLMN IDs, NIDs, or CAG IDs only after authentication, and prioritize access to dedicated cells.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cells transmit network identifiers (PLMN ID, CAG ID, NID) to enable device access, then access capability is improved, but network privacy and security deteriorate due to eavesdropping
Solution Approach 1:
The network node performs authentication and authorization procedures before transmitting any network identifier information to the wireless device. This preliminary action ensures that only authorized devices receive sensitive network association information, preventing eavesdroppers from obtaining such data through passive listening.
Solution Approach 2:
The patent introduces a trusted network node as an intermediary that controls the distribution of network identifier information. This intermediary authenticates devices and selectively provides identifier information only to authorized devices, acting as a gatekeeper that protects network privacy while enabling legitimate access.
2Object-affected harmful factors
If network identifiers are concealed from unauthorized parties, then privacy and security are improved, but access capability deteriorates for legitimate devices
Solution Approach 1:
The network node performs authentication and authorization procedures before transmitting any network identifier information to the wireless device. This preliminary action ensures that only authorized devices receive sensitive network association information, preventing eavesdroppers from obtaining such data through passive listening.
Solution Approach 2:
The patent introduces a trusted network node as an intermediary that controls the distribution of network identifier information. This intermediary authenticates devices and selectively provides identifier information only to authorized devices, acting as a gatekeeper that protects network privacy while enabling legitimate access.
3Object-affected harmful factors
If secured NAS signaling is used for authentication, then security is improved, but signaling complexity increases
Solution Approach 1:
The patent leverages the existing NAS signaling framework, which is already a universal and trusted communication channel between devices and network nodes. By utilizing this existing multi-functional signaling mechanism for authentication and identifier distribution, the patent avoids creating a separate complex signaling system while still providing enhanced security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method performed by a wireless device (12). The method comprises performing, over a first cell (14) associated with a public network, a non-access stratum (NAS) procedure in which the wireless device (12) is authenticated as being authorized to access a non-public network. The method also comprises after performing the NAS procedure, receiving from the first cell (14) a mobility command that commands the wireless device (12) to perform a mobility procedure towards a second cell (16) associated with the non-public network.