EAP-Based GBA Authentication Extensibility for 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing generic bootstrapping architecture (GBA) authentication methods rely on HTTP, which may not be extensible to support future authentication protocols and additional application scenarios, such as 5G AKA.
Innovation Solution
An extended authentication method based on the Extensible Authentication Protocol (EAP) is introduced, allowing User Equipment (UE) and Bootstrapping Server Function (BSF) to complete GBA AKA authentication, with the inclusion of a Bootstrapping Transaction Identifier (B-TID) and key lifetime in the EAP AKA authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If GBA authentication uses HTTP protocol, then authentication can be completed between UE and BSF, but the system lacks extensibility to support future authentication protocols and application scenarios
Solution Approach 1:
The patent applies universality by making the EAP server capable of supporting multiple authentication protocols (AKA, 5G AKA, and other EAP-based protocols) through a single unified platform. The EAP server can dynamically select and execute different authentication methods based on the protocol type indicated in authentication requests, eliminating the need for separate HTTP-based GBA authentication and future protocol implementations.
2Adaptability or versatility
If GBA authentication is extended to support 5G AKA and other protocols, then adaptability improves, but the authentication process complexity increases
Solution Approach 1:
The patent introduces an EAP server as an intermediary component between the UE and the authentication infrastructure. This EAP server acts as a mediator that receives authentication requests from UEs, determines the appropriate protocol type, executes the corresponding authentication method, and manages key distribution. This intermediary approach simplifies the overall authentication process by centralizing protocol management and selection logic.
Solution Approach 2:
The patent applies dynamics by enabling the EAP server to dynamically select and switch between different authentication protocols based on the request type. The server can adaptively choose between AKA, 5G AKA, or other EAP-based protocols during runtime, allowing the authentication system to flexibly respond to different service requirements without predetermined fixed configurations.
3Adaptability or versatility
If EAP-based GBA AKA authentication is implemented, then extensibility to future protocols is improved, but compatibility with existing HTTP-based GBA systems may be affected
Solution Approach 1:
The patent applies universality by designing the EAP server to support multiple authentication protocols (AKA, 5G AKA, and other EAP-based protocols) through a single unified platform. The EAP server can dynamically select and execute different authentication methods based on the protocol type indicated in authentication requests, eliminating the need for separate HTTP-based GBA authentication and future protocol implementations.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
This application provides an extended authentication method and apparatus for a generic bootstrapping architecture, and a storage medium. The method includes: A first network element obtains a B-TID and a key lifetime; and the first network element sends the B-TID and the key lifetime to the terminal, so that the terminal performs EAP-based GBA AKA authentication with the first network element based on the B-TID and the key lifetime. In this way, the terminal and the first network element complete the GBA AKA authentication based on an EAP.