5G Message Service Identity Authentication for Non-3GPP Users

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G networks face challenges in authenticating and authorizing users who input commands via voice, image, or fingerprint without a 3GPP subscription, and in identifying the target recipient when the voice command involves a UE whose identifier is not known to the network, especially in scenarios where multiple users share devices or use services like shared bike services.

Innovation Solution

A 5G message service architecture is proposed, including a 5G message service management function and gateway, which performs secondary authentication and authorization, and identifies recipients through a subscription/notification model, using a 5G message broker to facilitate message transfer between UEs and application servers, and between different UEs, supporting various input types like voice, image, and video.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a 5G network uses traditional authentication methods requiring 3GPP subscription, then network security is maintained, but users sharing devices or using shared services cannot be authenticated

Engineering Contradiction:
Improveauthentication capabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an identity service as an intermediary layer between the user and the 5G network authentication system. This identity service manages alternative identity information (non-3GPP subscriptions) and translates them into forms that the network can authenticate, allowing device sharing and shared services while maintaining security through the mediation of identity mapping and verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If the network uses voice or biometric content for authentication, then user identification accuracy improves, but the complexity of handling multiple input types increases

Engineering Contradiction:
Improveuser identification accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The identity service is designed as a universal system that can handle multiple types of input (voice, biometric, other forms) through a single unified interface. The service prepares messages containing various input types and processes them through standardized authentication procedures, allowing the system to support diverse authentication methods without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the network delivers messages through control plane, then message delivery reliability improves, but the time required for authentication and authorization increases

Engineering Contradiction:
Improvemessage delivery reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The identity service performs preliminary authentication and prepares identity information before the actual message delivery process. By pre-processing identity verification and preparing authentication credentials in advance, the system reduces the time required during the actual message delivery while maintaining control plane reliability for the critical authentication functions

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12028707B2Apparatus, system, method, and computer-readable medium for performing a message service and identity service in a 5G network
Publication Date: 2024.07.02 IPLA HLDG INC
  • US12028707B2 patent drawing
  • US12028707B2 patent drawing
  • US12028707B2 patent drawing

AI summary

A first apparatus includes a processor, a memory, and communication circuitry. The first apparatus is connected to a communications network via its communication circuitry. The first apparatus further includes computer-executable instructions stored in the memory of the first apparatus which, when executed by the processor of the first apparatus, cause the first apparatus to: receive voice content or other biometric content of a user; prepare a message including the voice or other biometric content; send the message to the communications network or a second apparatus through a control plane of the communications network in order to authenticate and authorize the first apparatus and the user; receive a response message from the communications network or the second apparatus, wherein the response message includes authentication and authorization results for the first apparatus and identification information that identifies the user.