5G Core Authentication via External AAA for NPN Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G wireless communication systems face challenges in supporting non-public network (NPN) credentials for user equipment (UE) authentication, requiring customization of 3GPP network functions and legacy infrastructure, and lack flexibility in credential management and key generation.

Innovation Solution

Implementing an external Authentication, Authorization, and Accounting (AAA) server within the NPN domain, using a new interface (Nx) for authentication, allowing the AUSF to act as a proxy and derive security keys from a master key (MSK) provided by the AAA, independent of credential type, and maintaining compatibility with existing protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If 3GPP network functions are customized to support NPN credentials, then authentication capability is improved, but device complexity and infrastructure requirements worsen

Engineering Contradiction:
Improveauthentication capabilityVSAvoidinfrastructure requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an external AAA server as an intermediary authentication entity that handles NPN credential verification. This mediator approach allows the 5G core network to authenticate UEs using NPN credentials without customizing internal 3GPP network functions, thereby improving authentication capability while avoiding increased device complexity and infrastructure requirements within the core network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If external AAA server is used for authentication, then flexibility in credential management is improved, but system complexity worsens

Engineering Contradiction:
Improveflexibility in credential managementVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication function is segmented into separate components: the 5G core network handles standard 3GPP authentication, while an external AAA server handles NPN-specific authentication. This segmentation allows flexible credential management for different network types without increasing overall system complexity, as each component operates independently with well-defined interfaces.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If AUSF acts as proxy to derive security keys, then independence from credential type is improved, but key management complexity worsens

Engineering Contradiction:
Improveindependence from credential typeVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The AUSF acts as an intermediary proxy that receives master keys from the external AAA server and derives session keys independently of the original credential type. This mediator role enables the system to be independent from specific credential types (EAP-AKA', EAP-TLS, etc.) while maintaining manageable key complexity through standardized key derivation procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250274755A1Non-public network authentication in 5g
Publication Date: 2025.08.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250274755A1 patent drawing
  • US20250274755A1 patent drawing
  • US20250274755A1 patent drawing

AI summary

A method by a core network node of a core network of a wireless communication system for authenticating a user equipment, UE, to the core network includes receiving a first authentication request to authenticate the UE to the core network, determining that the UE should be authenticated by an external authentication entity that is external to the wireless communication system, transmitting a second authentication request to the external authentication entity, the second authentication request identifying the UE, receiving an authentication response from the external authentication entity verifying authenticity of the UE, the authentication response including a master key, and deriving a first key for securing communications with the UE from the master key.