EAP Secondary Authentication for 5G Network Slice Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication mechanisms in next-generation network systems are limited in supporting diverse authentication methods and credentials, and are not well-suited for the decoupling of authentication and authorization procedures across different network slices, especially with the increased complexity and requirements of 5G networks.

Innovation Solution

The implementation of an extensible authentication protocol (EAP) based secondary authentication method, where user equipment (UE) and user plane function (UPF) establish a user plane session for EAP-based authentication, enabling support for various authentication methods and credentials, and allowing independent authentication on a network slice-specific basis, even for multiple simultaneous connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional AKA authentication is used in 5G networks, then network access security is maintained, but the system cannot support diverse authentication methods and credentials required for different network slices and IoT devices

Engineering Contradiction:
Improveauthentication method diversityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into primary authentication (handled by SEAF using traditional AKA) and secondary authentication (handled by UPF using EAP). This segmentation allows each component to specialize: SEAF maintains security for network access while UPF provides versatile authentication for specific network slices and services, resolving the contradiction between security maintenance and authentication diversity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The UPF acts as an intermediary between the UE and the authentication servers for secondary authentication. It receives EAP authentication requests from UEs, forwards them to appropriate AAA servers, and manages the authentication process without requiring changes to the core security architecture. This intermediary role enables diverse authentication methods while maintaining system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If authentication and authorization are coupled in traditional networks, then procedural simplicity is maintained, but the system cannot provide independent authentication for different network slices with different QoS requirements

Engineering Contradiction:
Improvenetwork slice authentication independenceVSAvoidauthentication authorization procedure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments authentication and authorization into separate procedures: primary authentication establishes security context with SEAF, while secondary authentication with UPF provides slice-specific access control. This segmentation enables independent authentication for different network slices without complicating the overall procedure, as each slice can have its own EAP authentication parameters while sharing the same authorization framework.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple authentication servers are deployed for different network slices, then authentication flexibility is improved, but the load on the core network increases

Engineering Contradiction:
Improveauthentication method supportVSAvoidcore network load
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The UPF serves as a local intermediary that handles EAP authentication requests directly at the edge of the network. By processing secondary authentication locally rather than routing all authentication traffic through core network servers, the UPF reduces core network load while still supporting multiple authentication methods through EAP's extensibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Authentication capabilities are distributed to the local UPF rather than centralized in core network servers. Each UPF can be configured with specific EAP authentication methods relevant to its local network slices, providing authentication flexibility locally without requiring core network resources for every authentication decision.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10904756B2Authentication for next generation systems
Publication Date: 2021.01.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US10904756B2 patent drawing
  • US10904756B2 patent drawing
  • US10904756B2 patent drawing

AI summary

A method performed by a user equipment (UE) including establishing a primary authentication with a security anchor function, establishing a user plane (UP) session or connection with a UP function (UPF), receiving an extensible authentication protocol (EAP) based authentication request from the UPF, sending an EAP based authentication response to the UPF, and receiving an EAP based authentication result based on a verification response from an external authentication, authorization, and accounting (AAA) server. A method performed by a UPF includes establishing a UP session or connection to a UE, sending an EAP based authentication request to the UE, receiving an EAP based authentication response from the UE, forwarding the EAP based authentication response to an external AAA server, receiving a verification response from the external AAA server, and sending an authentication result to the UE based on the verification response from the external AAA server.