IMS Node Authentication Vector Generation for 5G Non-Public Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for 5G networks struggle to provide efficient authentication mechanisms for User Equipment (UEs) in Non-Public Networks (NPNs) that do not support USIM or IMSI-AKA based security mechanisms, requiring configuration with PLMN credentials for SIP Digest authentication.
Innovation Solution
A method involving a first IMS node, core nodes, and the UE to generate and use authentication vectors based on private identifiers, security keys, and AKMA procedures, allowing UEs to authenticate without needing USIM or IMSI-AKA, by deriving passwords from primary authentication keys for SIP Digest authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UEs in NPNs are configured with PLMN credentials for SIP Digest authentication, then authentication can be performed, but device complexity and configuration requirements increase
Solution Approach 1:
The UE performs self-authentication by deriving the password locally from the security key obtained during primary authentication in the access network. The UE generates the password using a key derivation function with the security key and a salt value, eliminating the need for manual configuration of PLMN credentials while ensuring reliable authentication.
Solution Approach 2:
The security key is obtained during the preliminary primary authentication process in the access network before SIP Digest authentication is needed. This preliminary action stores the security key in the UE, which is then used to derive the password for subsequent SIP Digest authentication, streamlining the overall authentication flow.
2Reliability
If traditional IMSI-AKA based security mechanisms are used, then authentication is secure, but compatibility with UEs not supporting USIM is reduced
Solution Approach 1:
The patent changes the authentication parameter from traditional IMSI-AKA based credentials to a password derived from a security key obtained during access network authentication. This parameter change enables UEs without USIM support to authenticate in the IMS network while maintaining security through the use of securely derived credentials.
Solution Approach 2:
The security key acts as an intermediary that bridges the access network authentication and the IMS authentication. Instead of directly using IMSI-AKA credentials, the security key obtained from the access network serves as an intermediate credential that can be transformed into the necessary password for SIP Digest authentication, enabling interoperability.
3Reliability
If UEs need to be configured with PLMN credentials, then authentication can be performed, but ease of operation is reduced
Solution Approach 1:
The UE autonomously generates the password for SIP Digest authentication by deriving it from the security key obtained during access network authentication. This self-service mechanism eliminates the need for network operators to manually configure PLMN credentials in UEs, significantly simplifying operation while maintaining reliable authentication.
Solution Approach 2:
The patent extracts the credential configuration requirement from the UE setup process. Instead of requiring UEs to be pre-configured with PLMN credentials, the system extracts the necessary authentication information (security key) from the access network authentication process and uses it to generate the required password dynamically.
Data Source
AI summary
A method performed by a first IP multimedia system, IMS, node, for handling authentication of a user equipment, UE, in a communication network. The method includes receiving a request from a second IMS node to retrieve an authentication vector. The request includes a private identifier generated from a subscription permanent identifier. The method further includes sending a request to retrieve an indication, where the request includes a subscription permanent identifier, receiving the indication, and generating the authentication vector using the received indication. In addition, the method includes sending the generated authentication vector to the second IMS node for authenticating the UE.


