Access Node Group Joining via Network-Layer Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Ultra-Dense Networks (UDN) and User-centric Ultra-Dense Networks (UUDN) scenarios, access points (APs) face challenges in securely joining Access Points Groups (APGs) due to dynamic membership and varying physical security environments, lacking a systematic method for secure APG joining.

Innovation Solution

The method involves network-layer mutual authentication between an access point and a local service center, using an access points group identifier and network-layer authentication parameters to ensure secure joining, where the access point authenticates the network side and returns an authentication response message to the local service center, allowing the access point to join the corresponding APG dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access points dynamically join and leave APGs to serve moving users, then the adaptability and user service quality are improved, but the security risk increases due to potential illegal AP infiltration

Engineering Contradiction:
Improvedynamic APG membershipVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary authentication actions before allowing APs to join APGs. The network entity performs authentication with the AP using authentication parameters before the AP can dynamically join the group, ensuring security is established in advance rather than reactively

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a network entity as an intermediary that mediates between APs and APGs. This intermediary performs authentication and authorization functions, controlling which APs can join which APGs, thereby maintaining security while enabling dynamic membership

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional fixed deployment of base stations is used, then the system complexity is reduced and operation is simplified, but the ability to serve moving users dynamically is insufficient

Engineering Contradiction:
Improvefixed deployment operationVSAvoiddynamic user service
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static, fixed deployment model into a dynamic one where APGs can be formed, modified, and dissolved based on user movement. The system dynamically assigns APs to different APGs as users move through coverage areas, enabling continuous service while maintaining simplified operation through automated management

Inventive Principle:
Principle #15Dynamics

3Reliability

If mutual authentication is implemented between AP and network entity, then the security is improved, but the joining process complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidjoining process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the AP and network entity autonomously perform mutual authentication using pre-configured parameters. The authentication process is self-contained and automated, reducing the need for manual intervention and simplifying the overall joining process despite the enhanced security measures

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3562185B1Method and device for joining access node group
Publication Date: 2024.05.01 DATANG MOBILE COMM EQUIP CO LTD
  • EP3562185B1 patent drawingFigure 1~2
  • EP3562185B1 patent drawingFigure 3
  • EP3562185B1 patent drawingFigure 4

AI summary

Embodiments of the present invention relate to the technical field of wireless communications, especially a method and device for joining an access node group (APG), for use in resolving the problem in the prior art of an access node being unable to join an APG securely. In the embodiments of the present invention, the access node performs network layer two-way authentication with a local service center after determining to join the APG; and the access node performs network configuration according to configuration information in a network configuration message after receiving the network configuration message sent by the local service center. Therefore, an APG corresponding to a user equipment follows the user equipment, and at the same time, it can be ensured that an access node may join the APG securely.