AAA Proxy Mediator for Non-3GPP Access Network Trustworthiness
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current standard specifications lack a feasible mechanism for determining the trustworthiness of non-3GPP access networks within a 3GPP-compliant packet data system, leading to potential security breaches and resource inefficiencies due to incomplete information about the security of IP links during roaming, especially when local breakout is selected.
Innovation Solution
A method and apparatus that utilize the visited network's 3GPP AAA Proxy or ePDG to assess the trustworthiness of non-3GPP access networks and signal this to the home network, considering available information and local policies, allowing the home network to make informed decisions about trustworthiness, even in roaming scenarios.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the home network makes trustworthiness decisions without complete information about IP link security, then decision-making process is simplified, but security reliability deteriorates
Solution Approach 1:
The visited network's AAA Proxy acts as an intermediary that collects trustworthiness information from the non-3GPP access network and provides it to the home network's AAA server. This mediator enables the home network to make informed trust decisions without directly acquiring complete IP link security information, thus resolving the contradiction between decision-making simplicity and security reliability.
2Measurement precision
If the home network waits for complete trustworthiness information before making decisions, then decision accuracy improves, but response time deteriorates
Solution Approach 1:
The visited network's AAA Proxy performs preliminary action by collecting and preparing trustworthiness information from the non-3GPP access network before the home network needs to make its decision. This advance preparation enables the home network to make accurate trust decisions faster, as the information is already aggregated and ready for transmission to the AAA server.
Solution Approach 2:
The system establishes a feedback mechanism where the AAA Proxy continuously monitors and reports trustworthiness information to the AAA server. This feedback loop enables the home network to receive timely updates on access network security status, allowing for accurate and timely trust decisions without waiting for complete information gathering.
3Reliability
If the home network treats all non-3GPP access networks as untrusted, then security is enhanced, but resource efficiency deteriorates
Solution Approach 1:
The system applies local quality by making trustworthiness decisions specific to each non-3GPP access network based on its individual security characteristics and the current network situation. Rather than uniformly treating all access networks as untrusted, the AAA server evaluates each network's trust status based on provided information, allowing trusted networks to operate with optimized resource allocation while maintaining security for untrusted networks.
4Adaptability or versatility
If the home network lacks information about local breakout security, then deployment flexibility improves, but trust decision accuracy deteriorates
Solution Approach 1:
The visited network's AAA Proxy serves as an intermediary that specifically gathers information about local breakout security configurations from non-3GPP access networks. This mediator enables the home network to receive detailed information about local breakout trust status, improving trust decision accuracy while preserving deployment flexibility across different network configurations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There are provided measures for trustworthiness decision making for access authentication, for example relating to the trustworthiness of non-3GPP access networks within a 3GPP-compliant packet data system, exemplarily comprising receiving an indication about a provisional trustworthiness of an access network, which provides packet data access for a roaming user, with respect to a visited network of said user from a network element of said visited network, determining the applicability of local breakout or home routing for each subscribed access point name of said user, and deciding about a final trustworthiness of said access network based upon the received provisional trustworthiness indication and the determined routing applicability for each subscribed access point name of said user.