External AAA Server for 5G Non-Public Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems, particularly in 5G networks, lack mechanisms for establishing security keys between user equipment (UE) and the network when the authentication entity is external to the network, leading to unprotected control and user plane traffic, especially in non-public networks (NPNs).
Innovation Solution
Implementing an external Authentication, Authorization, and Accounting (AAA) server acting as an Authentication Server Function (AUSF to establish security keys between the UE and the network, reducing the impact on the UE and minimizing changes to the primary authentication framework with minor enhancements on the network side.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an external AAA server is introduced to authenticate UE in non-public networks, then security key establishment is enabled and control/user plane traffic is protected, but the device complexity and network architecture complexity increase
Solution Approach 1:
The patent introduces an external AAA server as an intermediary authentication entity between the UE and the network. The AAA server receives authentication requests from the network, performs authentication using external credentials, and returns authentication results. This intermediary approach enables security key establishment for control and user plane traffic protection while maintaining a clear separation of authentication functions, thus resolving the contradiction between enabling security protection and avoiding excessive network architecture complexity.
2Reliability
If the primary authentication framework is modified to support external authentication entities, then secure connectivity in non-public networks is achieved, but the difficulty of implementation and integration increases
Solution Approach 1:
The patent segments the authentication framework into distinct functional components: the existing primary authentication framework remains intact, while a separate external authentication path is added through the AAA server. The network can selectively invoke either the traditional authentication method or the external AAA server authentication based on the network type (public vs. non-public). This segmentation allows secure connectivity in non-public networks without requiring extensive modifications to the core primary authentication framework, thus reducing implementation difficulty.
3Reliability
If security keys are established for protecting control and user plane traffic, then communication security is improved, but the processing overhead and authentication time increase
Solution Approach 1:
The patent implements preliminary authentication actions by having the AAA server pre-verify UE credentials using external authentication mechanisms before the UE attempts to access the network. The authentication result and security context are pre-established and stored, allowing the actual network access to proceed with minimal additional authentication steps. This preliminary action approach ensures communication security through proper key establishment while reducing the perceived authentication time during actual network access operations.
Data Source
AI summary
A method by a first core network (CN) node of a core network of a wireless communication system for authenticating a user equipment (UE) to the CN. The method includes receiving, from a second CN node, a first authentication request to authenticate the UE to the CN, and determining that the UE should be authenticated by an external authentication entity that is external to the wireless communication system. The first CN node transmits a second authentication request toward the external authentication entity, and receives a first authentication response verifying authenticity of the UE. The method further includes obtaining a key for securing communications with the UE based on the authentication response, and transmitting a second authentication response to the second CN node identifying the UE and including the key for securing communications with the UE.


