Authentication Key Selection for 5G UE Reliability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G communication systems, when the Authentication Center (AuC) server or database experiences errors, it leads to authentication failures for User Equipment (UE), preventing network access and communication services.
Innovation Solution
Implementing a method that allows User Equipment (UE) to use either a common authentication key or an Over The Air (OTA) key, selected based on a preset policy, to facilitate mutual authentication even when the AuC server or database is error-prone, by generating an authentication token using the appropriate key type.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AuC server or database is used for authentication, then authentication can be performed, but authentication fails when the AuC server or database experiences errors
Solution Approach 1:
The patent introduces a key selection unit as an intermediary component that mediates between the authentication request and the AuC server. When the AuC server is unavailable or erroneous, the key selection unit activates alternative authentication keys (such as common authentication keys or OTA keys) to enable continued authentication without direct dependency on the AuC server's availability.
Solution Approach 2:
The patent implements beforehand cushioning by pre-storing multiple authentication keys (common authentication keys, OTA keys) in the UE before the AuC server may fail. This preparatory measure ensures that when the primary authentication path fails, alternative keys are already available to maintain authentication functionality, thus cushioning against the harmful effect of AuC server errors.
2Device complexity
If a single authentication key is used, then the system is simple, but the system becomes vulnerable to AuC server or database errors
Solution Approach 1:
The patent applies universality by implementing a multi-functional authentication key management system. The UE is equipped with multiple authentication keys (first authentication key from AuC, common authentication key, OTA key) that can serve different functions and scenarios. The key selection unit dynamically chooses the appropriate key based on availability and reliability, making the system universally capable of handling various authentication situations.
Solution Approach 2:
The patent utilizes parameter changes by dynamically switching between different authentication keys based on the operational status of the AuC server. The system changes the authentication parameter (key type) from the primary AuC key to alternative keys (common key or OTA key) when the AuC server is erroneous or unavailable, thereby maintaining authentication reliability without significantly increasing complexity.
3Reliability
If multiple authentication keys are stored in UE, then authentication reliability improves, but the UE storage requirement increases
Solution Approach 1:
The patent applies local quality by storing different types of authentication keys with different characteristics in the UE. The common authentication key and OTA key are stored with specific properties (such as key type identifiers, validity conditions) that enable the key selection unit to distinguish and select the appropriate key based on local availability and reliability conditions, rather than uniformly storing all possible keys.
Data Source
AI summary
The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. A method and an apparatus of a server in a communication system are provided. The method includes receiving identifier information of a user equipment (UE), obtaining, if an error is detected for a first authentication key corresponding to the identifier information, information on a second authentication key for authenticating the UE, and authenticating the UE based on the information on the second authentication key. The server includes a transceiver configured to communicate with at least one of a network node and an external server, and a controller configured to receive identifier information of a UE, if an error is detected for a first authentication key corresponding to the identifier information, obtain information on a second authentication key for authenticating the UE, and authenticate the UE based on the information on the second authentication key.


