EAP Extensions for Unauthenticated UE Session Establishment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP access networks prevent unauthenticated user equipment from establishing sessions in trusted non-3GPP access networks, which is a problem since certain services, such as emergency sessions, need to be accessible to all requesting UEs regardless of authentication status.
Innovation Solution
The implementation of EAP extensions, specifically the TWAN-Info-Notification and TWAN-Conn-Notification messages, allows unauthenticated UEs to negotiate and establish connections in trusted non-3GPP access networks by supporting Single Connection Mode (SCM) and Multiple Connection Mode (MCM), enabling access to essential services like emergency sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication is required for session establishment in trusted non-3GPP access networks, then network security is improved, but accessibility to essential services like emergency sessions deteriorates
Solution Approach 1:
The patent changes the authentication parameter state by introducing a conditional authentication mechanism. Unauthenticated UEs are allowed to establish sessions with specific service parameters (emergency services) while authenticated UEs get full service access. This is implemented through the EAP extensions that negotiate authentication requirements based on service type, allowing emergency sessions without authentication while maintaining security for other services.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism through EAP extensions (TWAN-Info-Notification and TWAN-Conn-Notification messages). These intermediary messages facilitate a negotiated authentication process that allows unauthenticated UEs to access emergency services while maintaining security controls. The intermediary layer enables differentiated access policies without compromising overall network security.
2Adaptability or versatility
If unauthenticated UEs are allowed to establish sessions, then service accessibility is improved, but network security risk worsens
Solution Approach 1:
The patent applies local quality by implementing differentiated security policies for different services and UEs. Emergency services receive privileged access with relaxed authentication requirements, while other services maintain strict authentication controls. This is achieved through service-specific session parameters and EAP extension negotiations that tailor security requirements to the specific service being accessed, allowing unauthenticated emergency access without compromising security for authenticated services.
3Reliability
If authentication processes are implemented, then security control is improved, but complexity of access procedures worsens
Solution Approach 1:
The patent implements partial authentication action by allowing UEs to establish sessions with limited authentication (unauthenticated mode) for specific services like emergency calls. The EAP extensions provide optional authentication negotiation, meaning authentication is performed only when required and supported. This partial action approach reduces access procedure complexity for basic emergency services while maintaining the option for full authentication when needed, avoiding the complexity of mandatory authentication for all services.
Data Source
AI summary
An authentication server establishes a network connection to user equipment (UE) in a non-3GPP compliant access network. The authentication server obtains an identity for the UE and determines that the UE is unauthenticated and requesting establishment through a non-3GPP compliant access network. The authentication server negotiates a connection mode with the unauthenticated UE and negotiates connection parameters for the connection mode with the unauthenticated UE. The authentication server may then establish a network connection through the non-3GPP compliant access network to the UE.


