Merging EAP-Finish and NAS Messages for 5G Authentication Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing integration of EAP protocols in 3GPP 5G/NextGen networks is inefficient due to overlapping functionality between NAS and EAP frameworks, leading to increased roundtrips and energy consumption during fast authentication processes, particularly with the EAP-Finish/Re-auth message and NAS Security Mode Command message.

Innovation Solution

The proposed solution involves transmitting the EAP-Finish/Re-auth message within the NAS Security Mode Command message, along with a freshness parameter, to reduce overlapping behavior and enhance the efficiency of key derivation and re-authentication processes, allowing the UE to support ERP capabilities and optimize network messaging.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If EAP-Finish/Re-auth message and NAS Security Mode Command message are transmitted separately, then authentication security is maintained, but network messaging efficiency deteriorates and energy consumption increases

Engineering Contradiction:
Improvenetwork messaging efficiencyVSAvoidenergy consumption
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent combines the EAP-Finish/Re-auth message and the NAS Security Mode Command message into a single transmitted message. This merging eliminates redundant message transmissions, reduces signaling overhead, and decreases energy consumption while maintaining the security functions of both protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified message structure serves multiple authentication and security functions simultaneously. It performs both EAP re-authentication and NAS security mode command functions in a single transmission, reducing the number of roundtrips and improving network messaging efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication protocols are used, then protocol security is ensured, but authentication delay increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By merging the EAP-Finish/Re-auth message and NAS Security Mode Command message into a single transmission, the patent reduces the number of authentication roundtrips. This combination maintains the security integrity of both protocols while significantly reducing authentication delay.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If overlapping functionality between NAS and EAP frameworks is maintained, then protocol compatibility is preserved, but messaging redundancy increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidmessaging redundancy
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the overlapping functionalities of NAS and EAP frameworks into a unified message structure. This approach preserves protocol compatibility while eliminating messaging redundancy, reducing the complexity of the authentication process.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11818569B2Methods supporting authentication in wireless communication networks and related network nodes and wireless terminals
Publication Date: 2023.11.14 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11818569B2 patent drawing
  • US11818569B2 patent drawing
  • US11818569B2 patent drawing

AI summary

Some methods in a wireless communication network may include providing a first authentication key, and deriving a second authentication key based on the first authentication key, with the second authentication key being associated with the wireless terminal. Responsive to deriving the second authentication key, a key response message may be transmitted including the second authentication key and/or an EAP-Finish/Re-auth message. Some other methods in a wireless communication network may include receiving a key response message including a core network mobility management authentication key and an EAP-Finish/Re-auth message. Responsive to receiving the key response message, the network may initiate transmission of an EAP-Finish/Re-auth message and/or a freshness parameter used to derive the core network mobility management authentication key from the wireless communication network to the wireless terminal responsive to the key response message. Related wireless terminal methods are also discussed.