Identifier-Based Authentication for Fixed Network Residential Gateways
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G wireless communication systems lack detailed methods for determining whether authentication is required for legacy Fixed Network Residential Gateways (FN-RGs) and establishing necessary security protocols, as these devices are not 5G capable and cannot use standard 5G authentication mechanisms.
Innovation Solution
The UDM, AMF, or AUSF in the 5G core network determines that authentication is not required for FN-RGs based on device identifiers, using local configurations or subscription information, and establishes NAS security with dummy parameters to facilitate connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard 5G authentication mechanisms are used, then security is improved, but legacy FN-RGs cannot connect as they are not 5G capable
Solution Approach 1:
The patent introduces an intermediary authentication approach where the network determines authentication requirements based on device identifiers rather than requiring full 5G authentication. The UDM/AUSF/AMF acts as an intermediary by evaluating the FN-RG identifier and making a determination about authentication necessity, allowing legacy devices to connect through the 5G core network without implementing full 5G authentication capabilities.
Solution Approach 2:
The patent changes the authentication parameter from binary (authenticate/not authenticate) to a determined parameter where the network decides based on device type. The authentication requirement is transformed from a fixed protocol requirement to a dynamically determined parameter based on the FN-RG identifier, enabling legacy devices to be accommodated while maintaining security for devices that require it.
2Reliability
If authentication is required for all devices, then security is improved, but integration of legacy FN-RGs becomes complex and difficult
Solution Approach 1:
The patent extracts the authentication determination from the universal authentication process and creates a separate evaluation path for FN-RGs. Instead of requiring all devices to go through the same complex authentication process, the system extracts the identification and determination step, allowing FN-RGs to be evaluated separately and granted access without full authentication when appropriate.
Solution Approach 2:
The patent inverts the traditional authentication approach by assuming authentication is not required unless determined otherwise. Instead of requiring authentication by default and providing exemptions, the system starts with no authentication requirement and determines when authentication is necessary based on the device identifier, simplifying the process for legacy devices.
3Reliability
If full authentication processes are implemented for FN-RGs, then security is improved, but seamless integration is compromised
Solution Approach 1:
The patent performs preliminary determination of authentication requirements before the actual authentication process. By evaluating the FN-RG identifier in advance and determining that authentication is not required, the system avoids unnecessary authentication steps, enabling seamless integration while maintaining security for devices that need it.
Data Source
Figure 1A~1B
Figure 2
Figure 3
AI summary
A method performed by a core network node (300) of a wireless communication system includes receiving a (902) registration request to register a fixed network residential gateway, FN-RG, to the core network, obtaining (904) an identifier associated with the FN-RG, and determining (906), based on the identifier of the FN-RG, that authentication of the FN-RG by the core network is not required.