Authentication Failure Handling in Untrusted Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication devices face inefficiencies in managing authentication failures when attempting to access services through untrusted wireless networks, leading to repeated retries and unnecessary network resource consumption without clear failure reasons.
Innovation Solution
The implementation of error message mapping by network elements, such as ePDGs, to provide specific authentication failure messages to devices, allowing them to determine appropriate retry behaviors based on these messages, including back-off times and limited retry attempts, thereby preventing further access attempts until conditions change.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If wireless communication devices repeatedly retry authentication attempts without detailed failure information, then they may eventually succeed in accessing services, but network resources are wasted and power consumption increases
Solution Approach 1:
The patent implements a feedback mechanism where the network element provides detailed authentication failure cause information to the wireless communication device. This feedback enables the device to understand why authentication failed and adjust its retry behavior accordingly, avoiding unnecessary repeated attempts that consume power and network resources.
Solution Approach 2:
The wireless communication device autonomously determines its retry behavior based on the failure cause information received from the network. Instead of blindly retrying, the device self-adjusts its authentication strategy by interpreting the failure reasons and making intelligent decisions about whether to retry, when to retry, and under what conditions, thereby reducing unnecessary power consumption.
2Reliability
If wireless communication devices repeatedly retry authentication attempts without detailed failure information, then they may eventually succeed in accessing services, but network resources are consumed inefficiently
Solution Approach 1:
The network element provides specific authentication failure cause information to the wireless communication device, enabling it to understand the reason for failure. This feedback mechanism allows the device to make informed decisions about retry attempts, reducing unnecessary network signaling and resource consumption while maintaining authentication success rates.
Solution Approach 2:
The wireless communication device autonomously manages its authentication retry behavior by interpreting failure cause information from the network. The device self-determines whether to retry based on the specific failure reasons received, thereby optimizing network resource utilization without requiring continuous network control or intervention.
3Productivity
If detailed authentication failure messages are provided to devices, then retry behavior can be optimized, but message processing complexity increases
Solution Approach 1:
The authentication failure information is segmented into distinct cause categories (e.g., invalid credentials, network unreachable, service unavailable). This segmentation allows the wireless communication device to process and interpret failure reasons in a structured manner, matching specific causes with predefined retry strategies, thereby reducing processing complexity while maintaining high authentication handling efficiency.
Solution Approach 2:
The patent changes the parameter of failure information from generic error messages to specific cause-coded messages. This parameter change enables the device to efficiently process authentication failures by comparing received cause codes against a predefined set of known causes and their corresponding retry behaviors, simplifying the decision-making process while improving authentication handling efficiency.
Data Source
AI summary
Apparatus and methods to support authentication failure handling by network elements and by a wireless communication device when attempting access to services through non-cellular wireless networks by the wireless communication device are disclosed. Error messages received from evolved packet core (EPC) network elements, such as an authentication, authorization, and accounting (AAA) server, are mapped to failure messages provided to wireless communication devices by internetworking equipment, such as an evolved packet data gateway (ePDG). The wireless communication device determines a failures cause based on the failure messages and disallows retry attempts until select criteria are satisfied.


