Identifier-Based Authentication for Fixed Network Residential Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G wireless communication systems lack detailed methods for determining whether authentication is required for legacy Fixed Network Residential Gateways (FN-RGs) and establishing necessary security protocols, as these devices are not 5G capable and cannot use standard 5G authentication mechanisms.

Innovation Solution

The UDM, AMF, or AUSF in the 5G core network determines that authentication is not required for FN-RGs based on device identifiers, using local configurations or subscription information, and establishes NAS security with dummy parameters to facilitate connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard 5G authentication mechanisms are used, then security is improved, but legacy FN-RGs cannot connect as they are not 5G capable

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility with legacy devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary authentication approach where the network determines authentication requirements based on device identifiers rather than requiring full 5G authentication. The UDM/AUSF/AMF acts as an intermediary by evaluating the FN-RG identifier and making a determination about authentication necessity, allowing legacy devices to connect through the 5G core network without implementing full 5G authentication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameter from binary (authenticate/not authenticate) to a determined parameter where the network decides based on device type. The authentication requirement is transformed from a fixed protocol requirement to a dynamically determined parameter based on the FN-RG identifier, enabling legacy devices to be accommodated while maintaining security for devices that require it.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication is required for all devices, then security is improved, but integration of legacy FN-RGs becomes complex and difficult

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication determination from the universal authentication process and creates a separate evaluation path for FN-RGs. Instead of requiring all devices to go through the same complex authentication process, the system extracts the identification and determination step, allowing FN-RGs to be evaluated separately and granted access without full authentication when appropriate.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent inverts the traditional authentication approach by assuming authentication is not required unless determined otherwise. Instead of requiring authentication by default and providing exemptions, the system starts with no authentication requirement and determines when authentication is necessary based on the device identifier, simplifying the process for legacy devices.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If full authentication processes are implemented for FN-RGs, then security is improved, but seamless integration is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidintegration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary determination of authentication requirements before the actual authentication process. By evaluating the FN-RG identifier in advance and determining that authentication is not required, the system avoids unnecessary authentication steps, enabling seamless integration while maintaining security for devices that need it.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3935801B1Authentication decision for fixed network residential gateways
Publication Date: 2025.10.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3935801B1 patent drawingFigure 1A~1B
  • EP3935801B1 patent drawingFigure 2
  • EP3935801B1 patent drawingFigure 3

AI summary

A method performed by a core network node (300) of a wireless communication system includes receiving a (902) registration request to register a fixed network residential gateway, FN-RG, to the core network, obtaining (904) an identifier associated with the FN-RG, and determining (906), based on the identifier of the FN-RG, that authentication of the FN-RG by the core network is not required.