Joint Authentication for Private Network Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In private mobile networks, especially those deployed by enterprises, there is a need for a joint authentication mechanism that combines cellular network authentication functions with enterprise authentication components to ensure secure access to the network, as existing methods may not adequately protect enterprise IT equipment and can lead to loss of control by Mobile Network Operators.
Innovation Solution
A method and system for jointly authenticating user equipment (UE) in a private network and a public network, involving a Private Subscriber Authentication Function (PSAF) that interacts with an Access and Mobility Management Function (AMF)/Security Anchor Function (SEAF) and a Unified Data Management (UDM) or Lightweight Directory Access Protocol (LDAP) server to verify authentication configurations and responses, ensuring secure access by combining multiple authentication layers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a standalone private mobile network is deployed completely isolated from the public network, then enterprise control and security are improved, but network complexity and isolation requirements increase
Solution Approach 1:
The authentication system is segmented into two independent but coordinated parts: the public network's 5G-AKA authentication and the enterprise's LDAP authentication. Each part operates independently with its own authentication vector and verification process, allowing the enterprise to maintain control while using shared infrastructure.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the UE must satisfy both the public network's SEAF and the enterprise's LDAP server. This intermediary layer coordinates between the two networks, enabling the UE to access enterprise resources only after passing both authentication layers.
2Reliability
If traditional 5G-AKA authentication is used alone, then network simplicity is maintained, but security for enterprise IT equipment is insufficient
Solution Approach 1:
The patent merges two authentication frameworks (5G-AKA and LDAP) into a unified joint authentication process. The UE's authentication credentials are verified against both the public network's subscription database and the enterprise's LDAP directory, combining the security strengths of both systems.
Solution Approach 2:
The authentication process is extended from a single-dimension (5G-AKA only) to a two-dimension framework by adding the LDAP authentication layer. This dimensional expansion allows verification of both network access rights and enterprise resource access rights simultaneously.
3Reliability
If joint authentication with multiple frameworks is implemented, then security control is improved, but authentication process complexity increases
Solution Approach 1:
The patent performs preliminary actions by obtaining both the 5G-AKA authentication vector from the UDM and the LDAP authentication credentials from the enterprise directory service before the actual authentication challenge. This preparation ensures that both authentication frameworks are ready to verify the UE simultaneously, streamlining the process.
Solution Approach 2:
The authentication system implements feedback mechanisms where the result of the 5G-AKA authentication influences the LDAP authentication process and vice versa. The SEAF and LDAP server exchange authentication results to determine the final access decision, creating a coordinated feedback loop that manages complexity.
Data Source
AI summary
The present disclosure is related to network nodes and methods at the network nodes for jointly authenticating a user equipment (UE). A method at a first network node in a first network for jointly authenticating a CE in the first network and a second network comprises: receiving, from a second network node in the second network, a first authentication request for the UE: determining whether the UE is successfully authenticated or not at least partially based on one or more authentication configurations for the first network: and transmitting, to the second network node, a first authentication response indicating whether the UE is successfully authenticated or not based on a result of the determination.


