ePDG Authentication Proxy for Untrusted Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is no established mechanism for carrying user credentials between a user equipment (UE) and the 3GPP network when connected via an untrusted non-3GPP access network, hindering external authentication support over untrusted access networks.
Innovation Solution
A method and apparatus are developed to create and send authentication requests across unsecured access networks, using key information exchange mechanisms to facilitate authentication data transfer between the UE and the communication network, and subsequently to a packet data network, through binding update messages that include authentication and identity information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an IPSec tunnel is established between UE and ePDG over untrusted non-3GPP access network, then secure communication channel is provided, but no mechanism exists to carry user credentials for external authentication
Solution Approach 1:
The ePDG acts as an intermediary between the UE and external AAA servers. The patent enables the ePDG to receive authentication data from the UE through IKEv2 messages and forward it to external AAA servers, thus mediating the authentication process between untrusted access and external networks
Solution Approach 2:
The ePDG is enhanced to perform multiple functions: it not only establishes IPSec tunnels for secure communication but also acts as an authentication proxy by receiving, processing, and forwarding authentication data to external AAA servers, making it a multi-functional node in the network
2Adaptability or versatility
If authentication data is transmitted over untrusted non-3GPP access network, then external authentication becomes possible, but security risks increase due to lack of established mechanisms
Solution Approach 1:
The patent performs preliminary authentication actions by establishing an IPSec tunnel with the ePDG before transmitting authentication data. The IKEv2 protocol is used to pre-establish secure keys and encryption mechanisms, ensuring that subsequent authentication data transmission occurs over a protected channel
Solution Approach 2:
The ePDG serves as a trusted intermediary that receives authentication data from the UE through secure IKEv2 messaging and forwards it to external AAA servers. This mediator approach ensures that sensitive authentication data never traverses the untrusted access network in plain text
3Device complexity
If no PCO mechanism is defined between UE and ePDG, then implementation complexity is reduced, but ability to carry authentication credentials is lost
Solution Approach 1:
The patent extends the existing IKEv2 protocol to carry authentication data, making this established key exchange mechanism multi-functional. Instead of creating a new protocol, the invention leverages IKEv2's existing structure to also transport authentication credentials, avoiding additional complexity while gaining versatility
Data Source
AI summary
There are provided measures for supporting an authentication to an external packet data network over an untrusted access network, said measures exemplarily comprising authenticating a user equipment to a communication network providing connectivity for the user equipment across an unsecured access network in response to a first authentication request, wherein the authentication request is an authentication request of a key information exchange mechanism and includes authentication data, receiving a second authentication request for authenticating the user equipment towards a packet data network external to the communications network. The measures may further comprise creating a binding update message including the authentication data and identity information of the user received from the user equipment.


