Joint Authentication for Private Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In private mobile networks, especially those deployed by enterprises, there is a need for a joint authentication mechanism that combines cellular network authentication functions with enterprise authentication components to ensure secure access to the network, as existing methods may not adequately protect enterprise IT equipment and can lead to loss of control by Mobile Network Operators.

Innovation Solution

A method and system for jointly authenticating user equipment (UE) in a private network and a public network, involving a Private Subscriber Authentication Function (PSAF) that interacts with an Access and Mobility Management Function (AMF)/Security Anchor Function (SEAF) and a Unified Data Management (UDM) or Lightweight Directory Access Protocol (LDAP) server to verify authentication configurations and responses, ensuring secure access by combining multiple authentication layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a standalone private mobile network is deployed completely isolated from the public network, then enterprise control and security are improved, but network complexity and isolation requirements increase

Engineering Contradiction:
Improveenterprise controlVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into two independent but coordinated parts: the public network's 5G-AKA authentication and the enterprise's LDAP authentication. Each part operates independently with its own authentication vector and verification process, allowing the enterprise to maintain control while using shared infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the UE must satisfy both the public network's SEAF and the enterprise's LDAP server. This intermediary layer coordinates between the two networks, enabling the UE to access enterprise resources only after passing both authentication layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional 5G-AKA authentication is used alone, then network simplicity is maintained, but security for enterprise IT equipment is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges two authentication frameworks (5G-AKA and LDAP) into a unified joint authentication process. The UE's authentication credentials are verified against both the public network's subscription database and the enterprise's LDAP directory, combining the security strengths of both systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication process is extended from a single-dimension (5G-AKA only) to a two-dimension framework by adding the LDAP authentication layer. This dimensional expansion allows verification of both network access rights and enterprise resource access rights simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If joint authentication with multiple frameworks is implemented, then security control is improved, but authentication process complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions by obtaining both the 5G-AKA authentication vector from the UDM and the LDAP authentication credentials from the enterprise directory service before the actual authentication challenge. This preparation ensures that both authentication frameworks are ready to verify the UE simultaneously, streamlining the process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system implements feedback mechanisms where the result of the 5G-AKA authentication influences the LDAP authentication process and vice versa. The SEAF and LDAP server exchange authentication results to determine the final access decision, creating a coordinated feedback loop that manages complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240244429A1Joint authentication for private network
Publication Date: 2024.07.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240244429A1 patent drawing
  • US20240244429A1 patent drawing
  • US20240244429A1 patent drawing

AI summary

The present disclosure is related to network nodes and methods at the network nodes for jointly authenticating a user equipment (UE). A method at a first network node in a first network for jointly authenticating a CE in the first network and a second network comprises: receiving, from a second network node in the second network, a first authentication request for the UE: determining whether the UE is successfully authenticated or not at least partially based on one or more authentication configurations for the first network: and transmitting, to the second network node, a first authentication response indicating whether the UE is successfully authenticated or not based on a result of the determination.