EAP Secondary Authentication for 5G Network Slice Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication mechanisms in next-generation network systems are limited in supporting diverse authentication methods and credentials, and are not well-suited for the decoupling of authentication and authorization procedures across different network slices, especially with the increased complexity and requirements of 5G networks.
Innovation Solution
The implementation of an extensible authentication protocol (EAP) based secondary authentication method, where user equipment (UE) and user plane function (UPF) establish a user plane session for EAP-based authentication, enabling support for various authentication methods and credentials, and allowing independent authentication on a network slice-specific basis, even for multiple simultaneous connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional AKA authentication is used in 5G networks, then network access security is maintained, but the system cannot support diverse authentication methods and credentials required for different network slices and IoT devices
Solution Approach 1:
The authentication system is segmented into primary authentication (handled by SEAF using traditional AKA) and secondary authentication (handled by UPF using EAP). This segmentation allows each component to specialize: SEAF maintains security for network access while UPF provides versatile authentication for specific network slices and services, resolving the contradiction between security maintenance and authentication diversity.
Solution Approach 2:
The UPF acts as an intermediary between the UE and the authentication servers for secondary authentication. It receives EAP authentication requests from UEs, forwards them to appropriate AAA servers, and manages the authentication process without requiring changes to the core security architecture. This intermediary role enables diverse authentication methods while maintaining system simplicity.
2Adaptability or versatility
If authentication and authorization are coupled in traditional networks, then procedural simplicity is maintained, but the system cannot provide independent authentication for different network slices with different QoS requirements
Solution Approach 1:
The system segments authentication and authorization into separate procedures: primary authentication establishes security context with SEAF, while secondary authentication with UPF provides slice-specific access control. This segmentation enables independent authentication for different network slices without complicating the overall procedure, as each slice can have its own EAP authentication parameters while sharing the same authorization framework.
3Adaptability or versatility
If multiple authentication servers are deployed for different network slices, then authentication flexibility is improved, but the load on the core network increases
Solution Approach 1:
The UPF serves as a local intermediary that handles EAP authentication requests directly at the edge of the network. By processing secondary authentication locally rather than routing all authentication traffic through core network servers, the UPF reduces core network load while still supporting multiple authentication methods through EAP's extensibility.
Solution Approach 2:
Authentication capabilities are distributed to the local UPF rather than centralized in core network servers. Each UPF can be configured with specific EAP authentication methods relevant to its local network slices, providing authentication flexibility locally without requiring core network resources for every authentication decision.
Data Source
AI summary
A method performed by a user equipment (UE) including establishing a primary authentication with a security anchor function, establishing a user plane (UP) session or connection with a UP function (UPF), receiving an extensible authentication protocol (EAP) based authentication request from the UPF, sending an EAP based authentication response to the UPF, and receiving an EAP based authentication result based on a verification response from an external authentication, authorization, and accounting (AAA) server. A method performed by a UPF includes establishing a UP session or connection to a UE, sending an EAP based authentication request to the UE, receiving an EAP based authentication response from the UE, forwarding the EAP based authentication response to an external AAA server, receiving a verification response from the external AAA server, and sending an authentication result to the UE based on the verification response from the external AAA server.


