EAP Extensions for Unauthenticated UE Session Establishment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP access networks prevent unauthenticated user equipment from establishing sessions in trusted non-3GPP access networks, which is a problem since certain services, such as emergency sessions, need to be accessible to all requesting UEs regardless of authentication status.

Innovation Solution

The implementation of EAP extensions, specifically the TWAN-Info-Notification and TWAN-Conn-Notification messages, allows unauthenticated UEs to negotiate and establish connections in trusted non-3GPP access networks by supporting Single Connection Mode (SCM) and Multiple Connection Mode (MCM), enabling access to essential services like emergency sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is required for session establishment in trusted non-3GPP access networks, then network security is improved, but accessibility to essential services like emergency sessions deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidaccessibility to essential services
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the authentication parameter state by introducing a conditional authentication mechanism. Unauthenticated UEs are allowed to establish sessions with specific service parameters (emergency services) while authenticated UEs get full service access. This is implemented through the EAP extensions that negotiate authentication requirements based on service type, allowing emergency sessions without authentication while maintaining security for other services.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary authentication mechanism through EAP extensions (TWAN-Info-Notification and TWAN-Conn-Notification messages). These intermediary messages facilitate a negotiated authentication process that allows unauthenticated UEs to access emergency services while maintaining security controls. The intermediary layer enables differentiated access policies without compromising overall network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If unauthenticated UEs are allowed to establish sessions, then service accessibility is improved, but network security risk worsens

Engineering Contradiction:
Improveservice accessibilityVSAvoidnetwork security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing differentiated security policies for different services and UEs. Emergency services receive privileged access with relaxed authentication requirements, while other services maintain strict authentication controls. This is achieved through service-specific session parameters and EAP extension negotiations that tailor security requirements to the specific service being accessed, allowing unauthenticated emergency access without compromising security for authenticated services.

Inventive Principle:
Principle #3Local quality

3Reliability

If authentication processes are implemented, then security control is improved, but complexity of access procedures worsens

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements partial authentication action by allowing UEs to establish sessions with limited authentication (unauthenticated mode) for specific services like emergency calls. The EAP extensions provide optional authentication negotiation, meaning authentication is performed only when required and supported. This partial action approach reduces access procedure complexity for basic emergency services while maintaining the option for full authentication when needed, avoiding the complexity of mandatory authentication for all services.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10212594B2System and method for session establishment by unauthenticated user equipment
Publication Date: 2019.02.19 NOKIA OF AMERICA CORP
  • US10212594B2 patent drawing
  • US10212594B2 patent drawing
  • US10212594B2 patent drawing

AI summary

An authentication server establishes a network connection to user equipment (UE) in a non-3GPP compliant access network. The authentication server obtains an identity for the UE and determines that the UE is unauthenticated and requesting establishment through a non-3GPP compliant access network. The authentication server negotiates a connection mode with the unauthenticated UE and negotiates connection parameters for the connection mode with the unauthenticated UE. The authentication server may then establish a network connection through the non-3GPP compliant access network to the UE.