WLAN Authentication via Mobile Network Subscription Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for wireless local area networks (WLAN) are inefficient, particularly in free networks, as they require cumbersome registration processes or rely on telecom operator-specific solutions that limit interoperability across different operators' networks.
Innovation Solution
A method and system that utilize a user terminal's subscription information from a second network to derive a subscriber identity, allowing for authentication through a pre-determined format of user name and password, enabling seamless access to a first network by generating an authentication request message and acknowledging access rights based on successful authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If username/password authentication is used, then user identification is possible, but registration process becomes slow and frustrating
Solution Approach 1:
The system enables users to authenticate themselves automatically by utilizing subscription information already stored in their terminal devices. The authentication mechanism allows users to self-identify without requiring manual registration processes, as the system automatically extracts and utilizes subscription data from the terminal's stored information.
Solution Approach 2:
Subscription information is pre-stored in the terminal device before the authentication process begins. This preliminary storage of authentication data eliminates the need for time-consuming registration processes at the point of access, as the necessary identification information is already available in the terminal's memory or SIM card.
2Ease of operation
If EAP-SIM/EAP-AKA mechanisms are used, then authentication without pre-established passwords is achieved, but interoperability between different telecom operators is limited
Solution Approach 1:
The authentication system is designed to work universally across different telecom operators by extracting and utilizing subscription information that is commonly stored in terminal devices regardless of the operator. The system accepts authentication requests from any operator's network by processing the subscription data format, making the authentication mechanism multi-operator compatible without requiring specific operator agreements.
Solution Approach 2:
The system acts as an intermediary between different telecom operators and the WLAN network by translating and processing subscription information into a universal authentication format. This intermediary approach allows seamless authentication across operator boundaries without requiring direct integration agreements between operators and WLAN providers.
3Reliability
If mobile id solution is used, then secure key-data storage in SIM card is achieved, but access is limited to services specified by telecom operators
Solution Approach 1:
The system extracts the essential authentication elements (subscription information) from the secured SIM card storage and utilizes them for WLAN authentication. By taking out only the necessary identification data while maintaining the security of the SIM card's protected environment, the system enables broader service accessibility without compromising the security benefits of mobile id.
Solution Approach 2:
The authentication mechanism enables the SIM card's security features to serve multiple purposes beyond operator-specific services. By utilizing the subscription information stored in the SIM card for general WLAN authentication across different operators and networks, the system expands the versatility of mobile id while maintaining its security advantages.
Data Source
AI summary
A method for determining an access right of a user terminal to a first network, wherein the user terminal (110) includes a subscription of a second network (150). The method includes: receiving (310) an access request message (240) including a data record for a user name and a data record for a password; determining (320) that the records are in a pre-determined format and that at least one of them includes data from which a subscriber identity for the second network is derivable; generating (330) an authentication request message from the access server (140) to a server (160) configured to perform authentication related tasks in the second network; receiving (340) information on the outcome of the authentication of the subscriber in the second network, generating (350) an acknowledgement to the user terminal (110) indicating right to access to the first network.


