Non-3GPP Access Authentication for Gateway-Free Core Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G networks require non-3GPP access gateways for terminal devices accessing the core network, leading to increased network deployment costs and complexity, especially for devices lacking a NAS module.
Innovation Solution
A network device within the core network performs authentication and manages registration and session connections for terminal devices using non-3GPP access points without the need for a non-3GPP access gateway, facilitating direct L2 or L3 connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a non-3GPP access gateway is deployed to enable terminal devices to access the core network, then the core network can support untrusted non-3GPP access, but the network deployment cost and complexity increase
Solution Approach 1:
The patent extracts the authentication and session management functions from the traditional non-3GPP access gateway and relocates them directly to the core network's control plane and user plane elements. This allows terminal devices to access the core network through non-3GPP access points without requiring an intermediate access gateway, thereby reducing network deployment complexity while maintaining access capability.
Solution Approach 2:
The control plane network element and user plane network element in the core network are designed to handle both 3GPP and non-3GPP access types universally. The control plane element performs authentication and session management for both access types, while the user plane element forwards data packets for both access types, eliminating the need for separate non-3GPP access gateway infrastructure.
2Adaptability or versatility
If a non-3GPP access gateway is deployed to enable terminal devices to access the core network, then the core network can support untrusted non-3GPP access, but the network deployment cost increases
Solution Approach 1:
The patent extracts the authentication and session management functions from the traditional non-3GPP access gateway and relocates them directly to the core network's control plane and user plane elements. This eliminates the need to deploy separate non-3GPP access gateway infrastructure, thereby reducing network deployment cost while maintaining access capability.
Solution Approach 2:
The patent merges the functions of the non-3GPP access gateway with the existing core network elements. The control plane network element combines authentication, authorization, and session management functions, while the user plane network element combines data forwarding and policy enforcement functions, eliminating the need for separate gateway infrastructure and reducing deployment cost.
Data Source
AI summary
Embodiments of this disclosure provide a communication method, a network device, a storage medium, and a program product. In the communication method, a network device of a core network receives an access request from a non-3rd generation partnership project (3GPP)-technology-based access point, where the access request is used to enable a terminal device connected to the non-3GPP access point to access the core network. The network device performs authentication on the terminal device based on the access request; and if the network device determines that the authentication succeeds, the network device sends a connection identifier to a non-3GPP access device. The connection identifier is used to determine an L2 or L3 connection between the non-3GPP access point and the non-3GPP access device. The terminal device connected to the non-3GPP access point gains access to the core network without a non-3GPP access gateway.


