Dynamic Secondary Authentication Selection in 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP standards only support DN-AAA based secondary authentication/authorization mechanisms, limiting the ability to use alternative methods and providing insufficient access information for multiple authentication methods.
Innovation Solution
The proposed solution introduces a method and apparatus that allow for the selection and use of multiple secondary authentication/authorization methods, including SBI-based and DN-AAA based methods, by transmitting messages indicating available methods and access information to network entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If only DN-AAA based secondary authentication/authorization is supported as per current 3GPP standards, then the implementation is simple and follows existing standards, but the system lacks flexibility and cannot support alternative authentication methods
Solution Approach 1:
The patent implements dynamic selection of authentication methods by introducing a message that carries indicators for different authentication types (SBI-based and DN-AAA based). The system can dynamically choose which authentication method to use based on the received indicators and specific use cases, transforming the static single-method approach into a dynamic multi-method system.
Solution Approach 2:
The patent creates a universal authentication framework that can handle multiple authentication methods (SBI-based and DN-AAA based) through a common message structure and selection mechanism. This allows the system to perform multiple authentication functions using a single unified approach, rather than requiring separate dedicated mechanisms for each method.
2Adaptability or versatility
If multiple secondary authentication/authorization methods are supported, then the system gains flexibility and adaptability, but the device complexity and message processing requirements increase
Solution Approach 1:
The patent segments the authentication method selection into distinct indicators within the message structure. Each authentication method (SBI-based, DN-AAA based) is represented by a separate indicator that can be independently set and processed. This segmentation allows the receiving entity to process each indicator separately and make decisions based on specific authentication requirements without having to parse a monolithic complex structure.
Data Source
AI summary
Embodiments of the present disclosure provide a method and an apparatus for performing secondary authentication/authorization for a terminal device in a communication network. A method performed by a first network entity may comprise: receiving from a second network entity a message indicating at least one kind of a secondary authentication/authorization method. One of the at least one kind of a secondary authentication/authorization method is a service based interface, SBI, -based secondary authentication/authorization. According to embodiments of the present disclosure, a dynamic selection of a kind of secondary authentication/authorization from a plurality of kinds may be achieved.


