Wireless UE Authentication with Temporary Blacklisting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased flexibility in mobile device operability across different network types introduces new ways for nefarious users to bypass contractual obligations by using unauthorized access modules, such as SIM cards, to gain unauthorized access to premium networks.

Innovation Solution

Implementing a network authentication system that queries eligibility databases for device and module-based identifiers to manage and authenticate registrations, temporarily blacklisting devices that attempt unauthorized access, and sending error messages to users to rectify errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If device flexibility across different network types is increased, then device operability and adaptability improve, but network security and prevention of unauthorized access deteriorate

Engineering Contradiction:
Improvedevice operabilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication by querying eligibility databases before allowing network registration. Device identifiers and module identifiers are verified against subscription data in advance, preventing unauthorized devices from gaining network access while still allowing flexible multi-network operation for eligible devices

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If strict authentication is implemented to prevent unauthorized access, then network security improves, but device operability and ease of registration deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidregistration process
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The authentication system is segmented into multiple independent components: device identifier extraction, module identifier extraction, eligibility database queries, and registration decision logic. This modular approach maintains security through comprehensive verification while simplifying the user experience by automating the complex authentication process

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs self-verification by automatically querying eligibility databases and comparing device/module identifiers against subscription data without requiring manual user intervention. Error messages are automatically generated and communicated to users, enabling them to rectify issues independently

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If permanent blacklisting is used to block unauthorized devices, then network security improves, but ability to correct errors deteriorates

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiderror correction
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The blacklist is implemented as a dynamic, temporary mechanism rather than a permanent ban. Devices that fail authentication are blacklisted for a predetermined duration, allowing automatic removal and re-registration opportunities. This dynamic approach maintains security by blocking suspicious devices while providing error correction pathways for legitimate users

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12408033B2Device authentication in a wireless telecommunications network
Publication Date: 2025.09.02 T MOBILE US INC
  • US12408033B2 patent drawing
  • US12408033B2 patent drawing
  • US12408033B2 patent drawing

AI summary

Systems and methods for authenticating User Equipment (UE) are disclosed. The method includes a network obtaining a cross-registration status for the UE based on receiving a registration request from the UE. The network can execute a network registration response according to the cross-registration status that represents a permission given to the UE to register outside of an original network.