EAP-Based GBA Authentication Extensibility for 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing generic bootstrapping architecture (GBA) authentication methods rely on HTTP, which may not be extensible to support future authentication protocols and additional application scenarios, such as 5G AKA.

Innovation Solution

An extended authentication method based on the Extensible Authentication Protocol (EAP) is introduced, allowing User Equipment (UE) and Bootstrapping Server Function (BSF) to complete GBA AKA authentication, with the inclusion of a Bootstrapping Transaction Identifier (B-TID) and key lifetime in the EAP AKA authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If GBA authentication uses HTTP protocol, then authentication can be completed between UE and BSF, but the system lacks extensibility to support future authentication protocols and application scenarios

Engineering Contradiction:
ImproveextensibilityVSAvoidprotocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by making the EAP server capable of supporting multiple authentication protocols (AKA, 5G AKA, and other EAP-based protocols) through a single unified platform. The EAP server can dynamically select and execute different authentication methods based on the protocol type indicated in authentication requests, eliminating the need for separate HTTP-based GBA authentication and future protocol implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If GBA authentication is extended to support 5G AKA and other protocols, then adaptability improves, but the authentication process complexity increases

Engineering Contradiction:
Improveprotocol supportVSAvoidauthentication process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an EAP server as an intermediary component between the UE and the authentication infrastructure. This EAP server acts as a mediator that receives authentication requests from UEs, determines the appropriate protocol type, executes the corresponding authentication method, and manages key distribution. This intermediary approach simplifies the overall authentication process by centralizing protocol management and selection logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies dynamics by enabling the EAP server to dynamically select and switch between different authentication protocols based on the request type. The server can adaptively choose between AKA, 5G AKA, or other EAP-based protocols during runtime, allowing the authentication system to flexibly respond to different service requirements without predetermined fixed configurations.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If EAP-based GBA AKA authentication is implemented, then extensibility to future protocols is improved, but compatibility with existing HTTP-based GBA systems may be affected

Engineering Contradiction:
Improvefuture protocol supportVSAvoidbackward compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies universality by designing the EAP server to support multiple authentication protocols (AKA, 5G AKA, and other EAP-based protocols) through a single unified platform. The EAP server can dynamically select and execute different authentication methods based on the protocol type indicated in authentication requests, eliminating the need for separate HTTP-based GBA authentication and future protocol implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3817271B1Extensible authentication method and device based on generic bootstrapping architecture, and storage medium
Publication Date: 2025.04.23 HUAWEI TECH CO LTD
  • EP3817271B1 patent drawingFigure 1~2
  • EP3817271B1 patent drawingFigure 3
  • EP3817271B1 patent drawingFigure 4

AI summary

This application provides an extended authentication method and apparatus for a generic bootstrapping architecture, and a storage medium. The method includes: A first network element obtains a B-TID and a key lifetime; and the first network element sends the B-TID and the key lifetime to the terminal, so that the terminal performs EAP-based GBA AKA authentication with the first network element based on the B-TID and the key lifetime. In this way, the terminal and the first network element complete the GBA AKA authentication based on an EAP.