EPS AKA Authentication Failure Handling in LTE Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the LTE system, the frequent triggering of EPS AKA authentication procedures when NAS count values approach their maximum values leads to resource wastage due to unnecessary authentication processes, especially when the connection is released immediately upon failure.

Innovation Solution

A method and apparatus that determine whether a service is allowed as unauthenticated based on network policy, allowing the connection to continue if the service does not require authentication or if the UE is incapable of performing the AKA procedure, thereby avoiding immediate release and reducing unnecessary authentication triggers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the connection is released immediately when EPS AKA authentication procedure fails, then security is maintained, but resources are wasted due to unnecessary connection releases

Engineering Contradiction:
ImprovesecurityVSAvoidresource wastage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by differentiating the handling of authentication failures based on the specific service type. Critical services (voice, SMS) trigger connection release while non-critical services (data, emergency calls) maintain connections. This selective approach optimizes resource utilization while preserving security for essential services.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamics by making the connection release decision adaptive rather than static. The network entity dynamically evaluates service requirements, UE capabilities, and authentication failure reasons to determine whether to release or maintain the connection, allowing flexible response to different operational scenarios.

Inventive Principle:
Principle #15Dynamics

2Reliability

If EPS AKA authentication procedure is frequently triggered when NAS count approaches maximum value, then security synchronization is maintained, but system resources are consumed excessively

Engineering Contradiction:
Improvekey synchronizationVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating authentication triggers based on service criticality and NAS count status. For non-critical services or when NAS count is below threshold, authentication is deferred, reducing unnecessary authentication triggers while maintaining security for critical services.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial action by performing authentication only when necessary rather than continuously. The network entity selectively triggers authentication based on service requirements and NAS count conditions, avoiding excessive authentication operations while ensuring security where needed.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If connection is maintained after authentication failure for unauthenticated services, then resource utilization improves, but security risks may increase

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by applying different security policies to different service types. Critical services maintain strict authentication requirements with connection release on failure, while non-critical services allow connection maintenance. This granular approach balances security and resource utilization based on service-specific requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary decision-making mechanism (the network entity's judgment unit) that evaluates authentication failure scenarios and determines appropriate actions. This intermediary layer mediates between security requirements and resource utilization goals, making informed decisions rather than applying blanket policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3531731B1Computer readable medium and apparatus for authentication
Publication Date: 2020.08.19 HUAWEI TECH CO LTD
  • EP3531731B1 patent drawingFigure 1
  • EP3531731B1 patent drawingFigure 2
  • EP3531731B1 patent drawingFigure 3

AI summary

A method and an apparatus for authentication are disclosed. The method includes: deciding to release a connection or continue a current service according to native information and network policy after an AKA authentication procedure fails. When the EPS AKA authentication procedure fails, the connection is not released immediately in the present invention, but the connection is released or the current service is continued according to the native information and network policy, thus avoiding unnecessary release of connections and saving resources.