Authentication Vector Quintet for 5G Roaming Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in providing seamless 5G services to user equipment (UE) that roams from a 5G non-standalone (NSA) network to a 5G standalone (SA) network lies in authenticating the UE across different network deployment modes, as existing solutions fail to efficiently manage the transition and ensure secure authentication.
Innovation Solution
A communication method and device that generate and transmit an authentication vector quintet with a specific bit setting, enabling a 5G SA operator to provide 5G services to roaming UEs by generating a 5G authentication vector based on an authentication vector request indication, which includes an access network type identifier and a requesting node identifier, facilitating 5G AKA or EAP-AKA' authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a UE roams from a 5G NSA network to a 5G SA network, then the UE can access the 5G SA network, but authentication becomes complex and insecure due to different network deployment modes
Solution Approach 1:
The patent changes the parameter of authentication vector generation by introducing an authentication management field with a specific bit (0th bit) that indicates whether to use 5G AKA or EAP-AKA' authentication. This parameter change allows the system to adapt authentication methods based on network type, ensuring security while enabling roaming between NSA and SA networks.
Solution Approach 2:
The patent introduces an authentication management field as an intermediary element that mediates between the 5G core network and the authentication process. This field carries the authentication management information (AMF) that guides the authentication method selection, resolving the contradiction by providing a controlled interface for different authentication scenarios.
2Ease of operation
If existing authentication solutions are used for roaming UEs, then the authentication process is simple, but it fails to efficiently manage the transition between different network deployment modes
Solution Approach 1:
The patent applies preliminary action by pre-configuring the authentication management field with the appropriate authentication method indication before the authentication process begins. The 0th bit of the AMF is set in advance to indicate whether to use 5G AKA or EAP-AKA', allowing the authentication process to proceed efficiently without complex real-time decisions.
Solution Approach 2:
By changing the authentication vector generation process to include the authentication management field with specific bit settings, the system improves authentication efficiency while maintaining operational simplicity. The parameter change enables the network to efficiently select the appropriate authentication method based on the UE's network context.
3Area of stationary object
If a 5G SA operator provides services to roaming UEs from 5G NSA operators, then network coverage is extended, but the authentication mechanism becomes complex
Solution Approach 1:
The patent simplifies the authentication mechanism by using parameter changes in the authentication management field. The 0th bit of the AMF provides a concise indication of the authentication method, reducing the complexity of the authentication mechanism while enabling 5G SA operators to provide services to roaming UEs from 5G NSA operators.
Solution Approach 2:
The authentication management field serves multiple functions: it indicates the authentication method, adapts to different network deployment modes, and enables seamless roaming. This universal mechanism reduces overall system complexity by consolidating multiple authentication scenarios into a single field.
Data Source
AI summary
A communication method and a communications device, where the communication method includes: When a user equipment roams from a first network to a second network, a first core network device receives a first request, where the first request is a user authentication request or an authentication data request, where the first request carries an authentication vector request indication, where the second network is a 5G standalone network, where the first network is a 5G non-standalone network, and where the first core network device is in the first network. The first core network device generates an authentication vector quintet based on the authentication vector request indication, where a 0th bit of an authentication management field in the authentication vector quintet is set to 1. The first core network device sends a response to the first request, where the response to the first request carries the authentication vector quintet.


