External Subscription Authentication via 5G NPN Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no existing solution for implementing authentication of a terminal with external subscription in a non-public 5G mobile communication system (NPN) network.

Innovation Solution

A mobility management network element obtains external authentication indication information, sends a request message to the terminal, receives a NAS message, and communicates with an authentication server function network element to perform external authentication, obtaining an authentication result from a trusted third party to authenticate the terminal with external subscription.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the NPN allows terminals with external subscription to access the network, then the adaptability and service coverage are improved, but the authentication mechanism becomes more complex and security risks increase

Engineering Contradiction:
Improveservice coverageVSAvoidauthentication mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server function network element as an intermediary between the mobility management network element and the external entity. This mediator handles the complex authentication process by receiving authentication requests from the mobility management network element, communicating with the external entity, and returning authentication results, thereby isolating the complexity from the core network elements while enabling external subscription access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct functional components: the mobility management network element that initiates authentication, the authentication server function network element that processes authentication, and the external entity that performs actual verification. This segmentation allows each component to handle specific tasks independently, managing complexity through functional decomposition

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the NPN allows terminals with external subscription to access the network, then the adaptability is improved, but the security reliability deteriorates

Engineering Contradiction:
Improveservice coverageVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication server function network element serves as a security intermediary that verifies the credentials of external entities before allowing network access. This mediator ensures that only authenticated terminals with valid external subscriptions can access the NPN, maintaining security while enabling adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication verification through the authentication server function network element before granting network access to terminals with external subscriptions. This preliminary security check prevents unauthorized access and potential security threats before they can affect the network

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12598084B2External authentication method, communication apparatus, and communication system
Publication Date: 2026.04.07 HUAWEI TECH CO LTD
  • US12598084B2 patent drawing
  • US12598084B2 patent drawing
  • US12598084B2 patent drawing

AI summary

An external authentication method to implement authentication of a terminal with external subscription, where the method includes: A mobility management network element obtains external authentication indication information. The mobility management network element sends a first request message to a terminal based on the external authentication indication information, where the first request message is used to request external authentication. The mobility management network element receives a first non-access stratum (NAS) message from the terminal. The mobility management network element sends related information of an external entity to an authentication server function network element based on the first NAS message, where the related information of the external entity is used to address the external entity, and where the external entity is configured to perform authentication on the terminal. The mobility management network element receives an external authentication result from the authentication server function network element.