Multisession PAP/CHAP Authentication for 5G WWC Gateways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in supporting legacy authentication protocols like PAP/CHAP within the 5G system without requiring additional legacy infrastructure, while accommodating multiple credentials per subscription and ensuring secure authentication for various IP sessions.

Innovation Solution

A method is introduced where additional authentication credentials are stored in the RG-LWAC data structure, allowing the AGF to authenticate multiple sessions using legacy credentials without relying on external servers, by employing AACI TLVs to manage PAP/CHAP authentication directly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If legacy authentication protocols (PAP/CHAP) are supported in 5G system, then compatibility with existing wireline CPE is improved, but system complexity increases due to need for legacy infrastructure

Engineering Contradiction:
Improvecompatibility with legacy wireline CPEVSAvoidlegacy infrastructure requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges legacy PAP/CHAP authentication functionality directly into the 5G core network's authentication mechanisms. The Access and Mobility Management Function (AMF) and Authentication Server Function (AUSF) are enhanced to handle both 5G-native authentication and legacy PAP/CHAP protocols through a unified authentication interface, eliminating the need for separate legacy authentication servers and reducing infrastructure complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server function is designed with multi-functionality to handle multiple authentication protocols simultaneously. The AUSF can process 5G-AKA, EAP-AKA', and legacy PAP/CHAP authentication methods through a single authentication interface, allowing the 5G system to support diverse CPE devices with different authentication capabilities without requiring protocol-specific infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple credentials are associated with single subscription, then support for multiple wireline IP sessions is improved, but credential management complexity increases

Engineering Contradiction:
Improvesupport for multiple wireline IP sessionsVSAvoidcredential management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments credential storage and management by organizing multiple credentials under a single subscription in a structured format. Each credential is stored as a separate authentication credential object within the Unified Data Management (UDM) system, allowing individual credentials to be independently managed, retrieved, and associated with specific PDU sessions while maintaining overall subscription-level organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The AMF acts as an intermediary between the AUSF and the data storage functions (UDM/UDR). It receives authentication requests, determines which credential to use based on session context, and coordinates with the AUSF to retrieve and validate the appropriate credential from the subscription's credential pool, simplifying the complexity of managing multiple credentials by providing a centralized coordination point.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If legacy AAA servers are decommissioned, then 5G infrastructure simplification is improved, but ability to authenticate legacy sessions is worsened

Engineering Contradiction:
ImproveAAA infrastructureVSAvoidlegacy session authentication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The 5G core network's authentication functions (AMF and AUSF) are enhanced to provide self-service capability for legacy authentication. The system can independently handle PAP/CHAP authentication requests without requiring external legacy AAA servers, using its own integrated authentication logic and credential storage to service both 5G-native and legacy authentication requests through unified interfaces.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12413973B2Multisession PAP/CHAP support for WWC
Publication Date: 2025.09.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12413973B2 patent drawing
  • US12413973B2 patent drawing
  • US12413973B2 patent drawing

AI summary

A method of providing multiple sets of legacy credentials to be applied to one subscription in a 5th generation (5G) system, where a subscriber initiates via legacy wireline access to the 5G system, multiple communications sessions each requiring respective different credential. The method comprises receiving, at a gateway function of the 5G system, subscriber legacy wireline access via a gateway node of the subscriber, registering the subscriber and identifying the subscriber subscription based on line identification (ID). In response to registering the subscriber, receiving subscription information from a subscription data structure of the 5G system; and initiating the multiple communications sessions between the subscriber and the 5G system by having the gateway function authenticate each of the communications sessions based on the line ID, relate the line ID to additional subscriber credentials stored in the subscription data structure, and apply additional subscriber credentials for authorization of respective individual communications sessions.