5G Security Association Failure Handling Via IKE Error Payloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods do not address how to handle security association establishment failures when user equipment attempts to connect to a 5G core network via untrusted non-3GPP access networks, leading to incomplete or unsuccessful network connections.

Innovation Solution

Implement an interworking function node and Access and Mobility Management function to manage network connections, generating response messages indicating connection failures over untrusted access networks, and utilizing IKE response messages with error payloads to handle authentication and secure connection establishment rejections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If security association establishment is attempted over untrusted non-3GPP access networks, then network connectivity is enabled, but authentication failures occur without proper error handling

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidconnection establishment reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the network sends specific error codes (e.g., 5GMM cause values) to the UE when security association establishment fails. This feedback enables the UE to understand the failure reason and take appropriate actions such as retrying with updated parameters or switching to alternative networks, thereby improving connection establishment reliability while maintaining network access capability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent establishes preliminary error handling frameworks and message structures (such as predefined error codes and response message formats) before authentication failures occur. This preliminary preparation ensures that when security association establishment fails, the system can immediately provide structured error information and guidance, preventing incomplete connections and improving reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication failure is rejected without detailed error information, then security is maintained, but troubleshooting and recovery are difficult

Engineering Contradiction:
Improvesecurity assuranceVSAvoidfailure recovery ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by providing different levels of error information based on the specific failure context. Rather than uniformly revealing all security details or providing generic error messages, the system sends targeted error codes (such as 5GMM cause values) that provide sufficient information for recovery without compromising overall security. This enables easy troubleshooting and recovery while maintaining security assurance.

Inventive Principle:
Principle #3Local quality

3Reliability

If comprehensive error handling messages are implemented, then connection recovery is improved, but message complexity increases

Engineering Contradiction:
Improveconnection recovery capabilityVSAvoidmessage structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent manages message complexity by changing parameters such as using standardized error code formats (5GMM cause values) and structured response message templates. These parameter changes allow comprehensive error information to be conveyed through predefined, compact message structures rather than complex custom protocols, improving connection recovery capability while controlling message structure complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250294356A1Method and apparatus for handling authentication failure during security association establishment
Publication Date: 2025.09.18 NOKIA SOLUTIONS & NETWORKS OY
  • US20250294356A1 patent drawing
  • US20250294356A1 patent drawing
  • US20250294356A1 patent drawing

AI summary

An interworking function in a core network system, such as a 5G core network, attempts to establish a secure association with user equipment (UE) in an untrusted access network. When the secure association is not accepted by the 5G core network, the UE receives from the core network a response including a message type indicating that Non-3GPP access to the 5G core network is not allowed. Upon receiving the response message, the UE ends the session by sending a 5G-Stop message formatted in an Extensible Authentication Protocol (EAP) response. The EAP-Response/5G-Stop message includes a message-id field with a 5G Stop value.