Group Authentication Aggregation for Wireless Device Re-authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP telecommunications networks face significant challenges in managing the heavy signaling load during massive re-authentication events of Massive Machine Type Communication (M-MTC) devices, leading to network congestion and inefficiencies in the Mobility Management Entity (MME) and Base Station (BS) interactions.

Innovation Solution

Implementing a group authentication method where the MME sends a group authentication request to the BS, which identifies and aggregates individual authentication responses from multiple User Equipments (UEs) into a single message, reducing the number of messages exchanged and optimizing the S1AP link utilization through Elliptic Curve Cryptography (ECC) operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual authentication requests are sent to each UE during mass re-authentication events, then authentication security is maintained, but S1AP signaling load increases significantly causing network congestion

Engineering Contradiction:
Improveauthentication securityVSAvoidS1AP signaling load
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines multiple individual authentication requests into a single group authentication request message. The MME sends one group authentication request containing authentication vectors for multiple UEs, and the BS aggregates multiple authentication response messages into a single group authentication response message. This merging approach maintains authentication security for each UE while dramatically reducing the quantity of S1AP signaling messages exchanged between MME and BS during mass re-authentication events.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The Base Station (BS) acts as an intermediary that receives individual authentication responses from multiple UEs and aggregates them into a single group authentication response message. This intermediary function allows the system to maintain individual authentication security while reducing overall signaling load, as the BS performs the aggregation operation without requiring individual MME-BS message exchanges for each UE.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If re-authentication is performed frequently to maintain security, then authentication reliability is improved, but network traffic and processing overhead increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By merging multiple individual authentication operations into a single group authentication process, the patent enables frequent re-authentication to be performed with reduced network overhead. The group authentication mechanism maintains authentication reliability for each UE while improving overall network efficiency during mass re-authentication scenarios by reducing the number of individual signaling exchanges required.

Inventive Principle:
Principle #5Merging (Combining)

3Quantity of substance

If group authentication aggregation is implemented, then S1AP signaling load is reduced, but message aggregation complexity increases

Engineering Contradiction:
ImproveS1AP signaling loadVSAvoidmessage aggregation complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The Base Station serves as an intermediary that handles the aggregation complexity, receiving individual authentication responses from multiple UEs and combining them into a single group authentication response message. This approach reduces S1AP signaling load between MME and BS while concentrating the aggregation complexity at the BS level, which is better equipped to handle the processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Base Station autonomously performs the aggregation of authentication responses without requiring complex coordination with the MME for each individual UE. The BS self-manages the aggregation process by collecting responses and creating the consolidated group authentication response message, thereby reducing overall system complexity while achieving signaling load reduction.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11343673B2Enhanced aggregated re-authentication for wireless devices
Publication Date: 2022.05.24 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11343673B2 patent drawing
  • US11343673B2 patent drawing
  • US11343673B2 patent drawing

AI summary

Methods and systems for group re-authentication of devices in a wireless telecommunication network are provided. According to one aspect, a method of operation of a base station in a wireless telecommunication network comprises receiving a group authentication request message from a mobility management entity, the group authentication request message comprising a group identifier; identifying at least one user equipment as belonging to a group identified by the group identifier; sending an individual authentication request message to each identified UE; receiving an authentication response from at least one of the identified UE; aggregating the received at least one authentication response to create a group authentication response message; and sending the group authentication response message to the mobility management entity.