ePDG Authentication Proxy for Untrusted Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no established mechanism for carrying user credentials between a user equipment (UE) and the 3GPP network when connected via an untrusted non-3GPP access network, hindering external authentication support over untrusted access networks.

Innovation Solution

A method and apparatus are developed to create and send authentication requests across unsecured access networks, using key information exchange mechanisms to facilitate authentication data transfer between the UE and the communication network, and subsequently to a packet data network, through binding update messages that include authentication and identity information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an IPSec tunnel is established between UE and ePDG over untrusted non-3GPP access network, then secure communication channel is provided, but no mechanism exists to carry user credentials for external authentication

Engineering Contradiction:
Improvesecure communicationVSAvoidexternal authentication support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The ePDG acts as an intermediary between the UE and external AAA servers. The patent enables the ePDG to receive authentication data from the UE through IKEv2 messages and forward it to external AAA servers, thus mediating the authentication process between untrusted access and external networks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The ePDG is enhanced to perform multiple functions: it not only establishes IPSec tunnels for secure communication but also acts as an authentication proxy by receiving, processing, and forwarding authentication data to external AAA servers, making it a multi-functional node in the network

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If authentication data is transmitted over untrusted non-3GPP access network, then external authentication becomes possible, but security risks increase due to lack of established mechanisms

Engineering Contradiction:
Improveauthentication data transferVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary authentication actions by establishing an IPSec tunnel with the ePDG before transmitting authentication data. The IKEv2 protocol is used to pre-establish secure keys and encryption mechanisms, ensuring that subsequent authentication data transmission occurs over a protected channel

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The ePDG serves as a trusted intermediary that receives authentication data from the UE through secure IKEv2 messaging and forwards it to external AAA servers. This mediator approach ensures that sensitive authentication data never traverses the untrusted access network in plain text

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If no PCO mechanism is defined between UE and ePDG, then implementation complexity is reduced, but ability to carry authentication credentials is lost

Engineering Contradiction:
Improveprotocol mechanismVSAvoidcredential carrying capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent extends the existing IKEv2 protocol to carry authentication data, making this established key exchange mechanism multi-functional. Instead of creating a new protocol, the invention leverages IKEv2's existing structure to also transport authentication credentials, avoiding additional complexity while gaining versatility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10581816B2External authentication support over an untrusted network
Publication Date: 2020.03.03 NOKIA TECHNOLOGIES OY
  • US10581816B2 patent drawing
  • US10581816B2 patent drawing
  • US10581816B2 patent drawing

AI summary

There are provided measures for supporting an authentication to an external packet data network over an untrusted access network, said measures exemplarily comprising authenticating a user equipment to a communication network providing connectivity for the user equipment across an unsecured access network in response to a first authentication request, wherein the authentication request is an authentication request of a key information exchange mechanism and includes authentication data, receiving a second authentication request for authenticating the user equipment towards a packet data network external to the communications network. The measures may further comprise creating a binding update message including the authentication data and identity information of the user received from the user equipment.