Multi-factor Authentication for IoT Devices in 5G Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G networks lack native multi-factor authentication (MFA) support for IoT devices, which increases the risk of unauthorized access and security threats, especially in enterprise environments that require high availability and secure connections.

Innovation Solution

The implementation of context-based multi-factor authentication (MFA) on the Authentication and Key Management for Applications (AKMA) layer, which includes fetching authentication information for IoT devices, applying MFA policies that define user or location restrictions, and enforcing these policies to establish secure sessions between IoT devices and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional single-factor authentication is used for IoT devices in 5G networks, then device connectivity and ease of operation are improved, but security and reliability deteriorate due to increased risk of unauthorized access

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication process is segmented into multiple independent factors (something the device has, something the device knows, something the device is) that work together to provide comprehensive security. Each factor can be independently verified, allowing the system to maintain security while providing flexibility in implementation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication framework that mediates between the IoT device and the network, implementing multi-factor authentication policies without requiring direct complex interactions between the device and network elements. This intermediary layer handles the complexity of MFA while presenting a simplified interface to end devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-factor authentication is implemented for IoT devices, then security and reliability are improved, but device complexity and processing requirements worsen

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent adds another dimension to authentication by implementing MFA policies at the network layer (5G core network) rather than requiring all complexity to be embedded in the IoT device itself. This dimensional shift allows simple IoT devices to benefit from enhanced security without increasing their own complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The authentication system is designed to be self-service oriented, where the network automatically manages multiple authentication factors and policies without requiring manual configuration or complex processing by the IoT device. The system autonomously verifies multiple factors and makes authentication decisions.

Inventive Principle:
Principle #25Self-service

3Reliability

If context-based MFA policies are enforced on the AKMA layer, then unauthorized access is reduced and security is improved, but network processing time and complexity worsen

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring MFA policies and authentication contexts in the 5G core network before actual authentication events occur. Context information such as device profiles, authorized users, and location-based rules are prepared in advance, allowing rapid evaluation during actual authentication without real-time complex processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes authentication parameters based on context, such as adjusting the number or type of factors required based on device risk profiles, location, time of day, or network conditions. This parameter adaptation allows the system to maintain high security when needed while reducing processing overhead during low-risk scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12309582B2Multi-factor authentication for IoT devices
Publication Date: 2025.05.20 CISCO TECHNOLOGY INC
  • US12309582B2 patent drawing
  • US12309582B2 patent drawing
  • US12309582B2 patent drawing

AI summary

Disclosed herein are systems, methods, and computer-readable media for enabling multi-factor authentication (MFA) for an Internet Of Things (IoT) device. In one aspect, a method includes receiving a network connection request from the IoT device to connect to a network. In one aspect, the method includes fetching authentication information for the device in response to the request. In one aspect, the method includes authenticating the device to the network. In one aspect, the method includes in response to the authentication of the device to the network, establishing a network connection between the IoT device and the network. In one aspect, the method includes applying the MFA policy. In one aspect, the method includes after successful compliance with the MFA policy establishing a session between the device and the application over the network.