External EAP Authentication for EPS–5GS Packet Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems, such as the Evolved Packet System (EPS) and 5G System (5GS), lack support for Extensible Authentication Protocol (EAP) based external authentication and authorization during packet data network connectivity, leading to inefficiencies in mobility procedures and compatibility issues with legacy applications.

Innovation Solution

Implementing methods and systems that enable EAP-based external authentication and authorization by using indicators to determine the capability of wireless terminals and networks to support specific authentication protocols, allowing seamless transfer of protocol data unit sessions between different network systems while ensuring compatibility and proper bearer identifier assignment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If EAP-based external authentication and authorization is implemented in EPS, then compatibility with 5GS and support for modern security protocols is improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvecompatibility with 5GSVSAvoidimplementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the EPS authentication system universal by incorporating EAP protocol support, allowing it to handle both traditional PAP/CHAP authentication and modern EAP-based authentication. This enables the EPS to function effectively in both standalone mode and in interworking scenarios with 5GS, eliminating the need for separate authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces capability indication mechanisms where UEs and networks预先 indicate their EAP support status through specific flags and parameters in signaling messages. This preliminary indication allows the network to determine the appropriate authentication method before the actual authentication process begins, avoiding complex runtime decision-making.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If EAP protocol is supported in EPS for legacy applications, then security performance is improved, but backward compatibility and ease of operation may be compromised

Engineering Contradiction:
Improvesecurity performanceVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic authentication method selection where the EPS network can adaptively choose between PAP, CHAP, and EAP authentication methods based on UE capability indications and network policies. This dynamic approach ensures that legacy applications can use simple PAP/CHAP while newer applications can benefit from enhanced EAP-based security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent utilizes parameter changes in signaling messages (such as capability flags and authentication type indicators) to control the authentication process. By modifying these parameters based on UE capabilities and network requirements, the system can switch between different authentication methods without changing the fundamental operational流程.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If capability indication for EAP support is implemented, then authentication efficiency is improved, but signaling overhead and device complexity increase

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsignaling overhead
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent merges the EAP capability indication with existing signaling messages in the EPS attachment and PDN connectivity establishment procedures. By incorporating capability flags into already-necessary signaling exchanges rather than introducing separate dedicated signaling messages, the patent achieves efficient capability communication with minimal additional overhead.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4256831B1A method for external authentication and authorization
Publication Date: 2025.09.10 ZTE CORP
  • EP4256831B1 patent drawingFigure 1
  • EP4256831B1 patent drawingFigure 2
  • EP4256831B1 patent drawingFigure 3

AI summary

A wireless communication method for use in a network entity is disclosed. The method comprises receiving, from a wireless terminal, an indicator associated with a capability of supporting at least one method of interacting with an external network for a packet data connection authentication and/or authorization of the external network, and performing a procedure based on the indicator, wherein the procedure is associated with establishing a packet data network connectivity in a second network.