Emergency EAP Parameter Exchange Without Mutual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In emergency access scenarios where a UE lacks a UICC with a known IMSI or does not have a UICC at all, the network cannot authenticate the UE, preventing the exchange of connection parameters.
Innovation Solution
A method and system that enable the exchange of connection parameters between a UE and a server using EAP messages, even without mutual authentication, by employing a simplified protocol during emergency attaches, such as through EAP-3GPP-LimitedService access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP-AKA(′) authentication protocol is used for emergency access, then security authentication is improved, but the protocol cannot proceed when UE lacks shared secrets or certificates
Solution Approach 1:
The patent applies partial authentication by exchanging only connection parameters without completing full mutual authentication. The network sends connection parameters to the UE in EAP messages, allowing the UE to establish emergency access with limited authentication rather than requiring complete EAP-AKA(′) authentication流程和shared secrets
Solution Approach 2:
The patent uses EAP messages as an intermediary mechanism to transfer connection parameters from the network to the UE. These messages serve as a mediator that enables parameter exchange without requiring the UE to have UICC or shared secrets, bridging the gap between security requirements and emergency access needs
2Reliability
If full EAP-AKA(′) authentication is required, then security is improved, but emergency access without UICC is prevented
Solution Approach 1:
The patent implements partial authentication by exchanging connection parameters through EAP messages without completing full mutual authentication. This allows emergency access to proceed with reduced authentication requirements, enabling UEs without UICC to still obtain necessary connection parameters for emergency services
Solution Approach 2:
The patent changes the authentication state parameters by allowing the network to send connection parameters in EAP messages without requiring the UE to have shared secrets or certificates. This parameter change enables the system to transition from requiring full authentication to allowing emergency access with minimal authentication
3Ease of operation
If connection parameters are exchanged without authentication, then emergency access is enabled, but security verification is lost
Solution Approach 1:
The patent applies partial authentication principles by exchanging connection parameters without completing full mutual authentication. The network sends connection parameters to the UE through EAP messages, providing enough information for emergency access while accepting reduced security verification
Solution Approach 2:
The patent uses EAP messages as an intermediary to transfer connection parameters from network to UE. This intermediary mechanism enables parameter exchange in a controlled manner, allowing emergency access to proceed while maintaining some level of protocol-based security framework
Data Source
AI summary
Enabling the exchange of connection parameters where a user equipment (UE) lacks a secret shared with the network (e.g. a server), such as key materials, and lacks a valid certificate. In some embodiments, the connection parameters may be exchanged via EAP messages. In certain aspects, and particularly with respect to emergency attach, a simplified protocol is used with limited overhead because the UE does not attempt to authenticate the network, and the network does not attempt to authenticate the UE.


