Access Management Entity Authentication in Shared 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G communication networks, implementing security protocols in an access network sharing environment is challenging, particularly when there is an indirect connection between a participating operator's core network and a shared access network.

Innovation Solution

The proposed solution involves establishing a secure connection between access management entities in different communication networks to facilitate user equipment authentication, enabling seamless access to the radio access network of one communication network while accessing the core network of another.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access network sharing with indirect connection is implemented, then network resource utilization and subscriber convenience are improved, but security management complexity and authentication difficulty increase

Engineering Contradiction:
Improvenetwork resource utilizationVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a serving access management entity as an intermediary between the user equipment and the home access management entity. This intermediary handles authentication requests and coordinates with both the radio access network and the home network, simplifying the security management process while enabling indirect network connections and resource sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct functional components: the serving access management entity handles local authentication coordination, while the home access management entity manages user credentials and security policies. This segmentation allows independent optimization of each component and simplifies overall security management in shared network environments.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If indirect connection between core network and shared access network is established, then access network sharing is enabled, but authentication procedure complexity increases

Engineering Contradiction:
Improveaccess network sharingVSAvoidauthentication procedure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The serving access management entity acts as a mediator that simplifies authentication procedures by handling local coordination tasks. It receives authentication requests from the radio access network, communicates with the home access management entity, and manages the authentication flow, thereby reducing procedure complexity while enabling indirect connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system establishes pre-configured secure connections and authentication frameworks between serving and home access management entities before actual user authentication occurs. This preliminary setup includes pre-shared secrets and trusted relationships, which simplify real-time authentication procedures by eliminating the need for complex runtime negotiation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure connection between access management entities is established, then user equipment authentication is facilitated, but network configuration complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Secure connections between access management entities are established in advance using pre-configured security parameters, trusted relationships, and pre-shared secrets. This preliminary security setup ensures reliable authentication while simplifying network configuration, as the secure channel is already in place before operational use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250039669A1Authentication in access network sharing environment
Publication Date: 2025.01.30 NOKIA TECHNOLOGIES OY
  • US20250039669A1 patent drawing
  • US20250039669A1 patent drawing
  • US20250039669A1 patent drawing

AI summary

Techniques are disclosed for user equipment authentication in a shared access network environment. In one example, a method comprises establishing, via a first access management entity in a first communication network that has a radio access network associated therewith, a secure connection with a second access management entity in a second communication network to which user equipment subscribes, and facilitating, via the first access management entity, authentication of the user equipment in conjunction with the second access management entity over the secure connection to enable the user equipment to utilize the radio access network of the first communication network to access the second communication network.