Authentication Failure Handling in Untrusted Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication devices face inefficiencies in managing authentication failures when attempting to access services through untrusted wireless networks, leading to repeated retries and unnecessary network resource consumption without clear failure reasons.

Innovation Solution

The implementation of error message mapping by network elements, such as ePDGs, to provide specific authentication failure messages to devices, allowing them to determine appropriate retry behaviors based on these messages, including back-off times and limited retry attempts, thereby preventing further access attempts until conditions change.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If wireless communication devices repeatedly retry authentication attempts without detailed failure information, then they may eventually succeed in accessing services, but network resources are wasted and power consumption increases

Engineering Contradiction:
Improveauthentication success rateVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements a feedback mechanism where the network element provides detailed authentication failure cause information to the wireless communication device. This feedback enables the device to understand why authentication failed and adjust its retry behavior accordingly, avoiding unnecessary repeated attempts that consume power and network resources.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The wireless communication device autonomously determines its retry behavior based on the failure cause information received from the network. Instead of blindly retrying, the device self-adjusts its authentication strategy by interpreting the failure reasons and making intelligent decisions about whether to retry, when to retry, and under what conditions, thereby reducing unnecessary power consumption.

Inventive Principle:
Principle #25Self-service

2Reliability

If wireless communication devices repeatedly retry authentication attempts without detailed failure information, then they may eventually succeed in accessing services, but network resources are consumed inefficiently

Engineering Contradiction:
Improveauthentication success rateVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The network element provides specific authentication failure cause information to the wireless communication device, enabling it to understand the reason for failure. This feedback mechanism allows the device to make informed decisions about retry attempts, reducing unnecessary network signaling and resource consumption while maintaining authentication success rates.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The wireless communication device autonomously manages its authentication retry behavior by interpreting failure cause information from the network. The device self-determines whether to retry based on the specific failure reasons received, thereby optimizing network resource utilization without requiring continuous network control or intervention.

Inventive Principle:
Principle #25Self-service

3Productivity

If detailed authentication failure messages are provided to devices, then retry behavior can be optimized, but message processing complexity increases

Engineering Contradiction:
Improveauthentication handling efficiencyVSAvoidmessage processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The authentication failure information is segmented into distinct cause categories (e.g., invalid credentials, network unreachable, service unavailable). This segmentation allows the wireless communication device to process and interpret failure reasons in a structured manner, matching specific causes with predefined retry strategies, thereby reducing processing complexity while maintaining high authentication handling efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of failure information from generic error messages to specific cause-coded messages. This parameter change enables the device to efficiently process authentication failures by comparing received cause codes against a predefined set of known causes and their corresponding retry behaviors, simplifying the decision-making process while improving authentication handling efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11051165B2Authentication failure handling for access to services through untrusted wireless networks
Publication Date: 2021.06.29 APPLE INC
  • US11051165B2 patent drawing
  • US11051165B2 patent drawing
  • US11051165B2 patent drawing

AI summary

Apparatus and methods to support authentication failure handling by network elements and by a wireless communication device when attempting access to services through non-cellular wireless networks by the wireless communication device are disclosed. Error messages received from evolved packet core (EPC) network elements, such as an authentication, authorization, and accounting (AAA) server, are mapped to failure messages provided to wireless communication devices by internetworking equipment, such as an evolved packet data gateway (ePDG). The wireless communication device determines a failures cause based on the failure messages and disallows retry attempts until select criteria are satisfied.