External AAA Server for 5G Non-Public Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, particularly in 5G networks, lack mechanisms for establishing security keys between user equipment (UE) and the network when the authentication entity is external to the network, leading to unprotected control and user plane traffic, especially in non-public networks (NPNs).

Innovation Solution

Implementing an external Authentication, Authorization, and Accounting (AAA) server acting as an Authentication Server Function (AUSF to establish security keys between the UE and the network, reducing the impact on the UE and minimizing changes to the primary authentication framework with minor enhancements on the network side.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an external AAA server is introduced to authenticate UE in non-public networks, then security key establishment is enabled and control/user plane traffic is protected, but the device complexity and network architecture complexity increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an external AAA server as an intermediary authentication entity between the UE and the network. The AAA server receives authentication requests from the network, performs authentication using external credentials, and returns authentication results. This intermediary approach enables security key establishment for control and user plane traffic protection while maintaining a clear separation of authentication functions, thus resolving the contradiction between enabling security protection and avoiding excessive network architecture complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the primary authentication framework is modified to support external authentication entities, then secure connectivity in non-public networks is achieved, but the difficulty of implementation and integration increases

Engineering Contradiction:
Improvesecure connectivityVSAvoidimplementation difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments the authentication framework into distinct functional components: the existing primary authentication framework remains intact, while a separate external authentication path is added through the AAA server. The network can selectively invoke either the traditional authentication method or the external AAA server authentication based on the network type (public vs. non-public). This segmentation allows secure connectivity in non-public networks without requiring extensive modifications to the core primary authentication framework, thus reducing implementation difficulty.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security keys are established for protecting control and user plane traffic, then communication security is improved, but the processing overhead and authentication time increase

Engineering Contradiction:
Improvecommunication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication actions by having the AAA server pre-verify UE credentials using external authentication mechanisms before the UE attempts to access the network. The authentication result and security context are pre-established and stored, allowing the actual network access to proceed with minimal additional authentication steps. This preliminary action approach ensures communication security through proper key establishment while reducing the perceived authentication time during actual network access operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230292125A1Security establishment for non-public networks
Publication Date: 2023.09.14 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20230292125A1 patent drawing
  • US20230292125A1 patent drawing
  • US20230292125A1 patent drawing

AI summary

A method by a first core network (CN) node of a core network of a wireless communication system for authenticating a user equipment (UE) to the CN. The method includes receiving, from a second CN node, a first authentication request to authenticate the UE to the CN, and determining that the UE should be authenticated by an external authentication entity that is external to the wireless communication system. The first CN node transmits a second authentication request toward the external authentication entity, and receives a first authentication response verifying authenticity of the UE. The method further includes obtaining a key for securing communications with the UE based on the authentication response, and transmitting a second authentication response to the second CN node identifying the UE and including the key for securing communications with the UE.