EPS AKA Authentication Failure Handling in LTE Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the LTE system, the frequent triggering of EPS AKA authentication procedures when NAS count values approach their maximum values leads to resource wastage due to unnecessary authentication processes, especially when the connection is released immediately upon failure.
Innovation Solution
A method and apparatus that determine whether a service is allowed as unauthenticated based on network policy, allowing the connection to continue if the service does not require authentication or if the UE is incapable of performing the AKA procedure, thereby avoiding immediate release and reducing unnecessary authentication triggers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the connection is released immediately when EPS AKA authentication procedure fails, then security is maintained, but resources are wasted due to unnecessary connection releases
Solution Approach 1:
The patent applies local quality by differentiating the handling of authentication failures based on the specific service type. Critical services (voice, SMS) trigger connection release while non-critical services (data, emergency calls) maintain connections. This selective approach optimizes resource utilization while preserving security for essential services.
Solution Approach 2:
The patent implements dynamics by making the connection release decision adaptive rather than static. The network entity dynamically evaluates service requirements, UE capabilities, and authentication failure reasons to determine whether to release or maintain the connection, allowing flexible response to different operational scenarios.
2Reliability
If EPS AKA authentication procedure is frequently triggered when NAS count approaches maximum value, then security synchronization is maintained, but system resources are consumed excessively
Solution Approach 1:
The patent applies local quality by differentiating authentication triggers based on service criticality and NAS count status. For non-critical services or when NAS count is below threshold, authentication is deferred, reducing unnecessary authentication triggers while maintaining security for critical services.
Solution Approach 2:
The patent implements partial action by performing authentication only when necessary rather than continuously. The network entity selectively triggers authentication based on service requirements and NAS count conditions, avoiding excessive authentication operations while ensuring security where needed.
3Productivity
If connection is maintained after authentication failure for unauthenticated services, then resource utilization improves, but security risks may increase
Solution Approach 1:
The patent applies local quality by applying different security policies to different service types. Critical services maintain strict authentication requirements with connection release on failure, while non-critical services allow connection maintenance. This granular approach balances security and resource utilization based on service-specific requirements.
Solution Approach 2:
The patent introduces an intermediary decision-making mechanism (the network entity's judgment unit) that evaluates authentication failure scenarios and determines appropriate actions. This intermediary layer mediates between security requirements and resource utilization goals, making informed decisions rather than applying blanket policies.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and an apparatus for authentication are disclosed. The method includes: deciding to release a connection or continue a current service according to native information and network policy after an AKA authentication procedure fails. When the EPS AKA authentication procedure fails, the connection is not released immediately in the present invention, but the connection is released or the current service is continued according to the native information and network policy, thus avoiding unnecessary release of connections and saving resources.