IMS Node Authentication Vector Generation for 5G Non-Public Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for 5G networks struggle to provide efficient authentication mechanisms for User Equipment (UEs) in Non-Public Networks (NPNs) that do not support USIM or IMSI-AKA based security mechanisms, requiring configuration with PLMN credentials for SIP Digest authentication.

Innovation Solution

A method involving a first IMS node, core nodes, and the UE to generate and use authentication vectors based on private identifiers, security keys, and AKMA procedures, allowing UEs to authenticate without needing USIM or IMSI-AKA, by deriving passwords from primary authentication keys for SIP Digest authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UEs in NPNs are configured with PLMN credentials for SIP Digest authentication, then authentication can be performed, but device complexity and configuration requirements increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidconfiguration requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The UE performs self-authentication by deriving the password locally from the security key obtained during primary authentication in the access network. The UE generates the password using a key derivation function with the security key and a salt value, eliminating the need for manual configuration of PLMN credentials while ensuring reliable authentication.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security key is obtained during the preliminary primary authentication process in the access network before SIP Digest authentication is needed. This preliminary action stores the security key in the UE, which is then used to derive the password for subsequent SIP Digest authentication, streamlining the overall authentication flow.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional IMSI-AKA based security mechanisms are used, then authentication is secure, but compatibility with UEs not supporting USIM is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidUE compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the authentication parameter from traditional IMSI-AKA based credentials to a password derived from a security key obtained during access network authentication. This parameter change enables UEs without USIM support to authenticate in the IMS network while maintaining security through the use of securely derived credentials.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The security key acts as an intermediary that bridges the access network authentication and the IMS authentication. Instead of directly using IMSI-AKA credentials, the security key obtained from the access network serves as an intermediate credential that can be transformed into the necessary password for SIP Digest authentication, enabling interoperability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If UEs need to be configured with PLMN credentials, then authentication can be performed, but ease of operation is reduced

Engineering Contradiction:
Improveauthentication functionVSAvoidconfiguration simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The UE autonomously generates the password for SIP Digest authentication by deriving it from the security key obtained during access network authentication. This self-service mechanism eliminates the need for network operators to manually configure PLMN credentials in UEs, significantly simplifying operation while maintaining reliable authentication.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the credential configuration requirement from the UE setup process. Instead of requiring UEs to be pre-configured with PLMN credentials, the system extracts the necessary authentication information (security key) from the access network authentication process and uses it to generate the required password dynamically.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20230269582A1Authentication in a communication network
Publication Date: 2023.08.24 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20230269582A1 patent drawing
  • US20230269582A1 patent drawing
  • US20230269582A1 patent drawing

AI summary

A method performed by a first IP multimedia system, IMS, node, for handling authentication of a user equipment, UE, in a communication network. The method includes receiving a request from a second IMS node to retrieve an authentication vector. The request includes a private identifier generated from a subscription permanent identifier. The method further includes sending a request to retrieve an indication, where the request includes a subscription permanent identifier, receiving the indication, and generating the authentication vector using the received indication. In addition, the method includes sending the generated authentication vector to the second IMS node for authenticating the UE.