Enhanced N17 Interface for 5G-EIR Secondary Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telecommunication networks face challenges in effectively authenticating user equipment (UE) to prevent fraudulent and stolen devices from accessing the network, particularly in non-3GPP access scenarios like Wi-Fi, where existing authentication methods are inadequate.

Innovation Solution

The implementation of an enhanced N17 interface between the Serving Call Session Control Function (S-CSCF) and the Fifth Generation (5G) Equipment Identity Register (5G-EIR) using a Representational State Transfer (REST) HTTP 2.0 protocol for secondary-level authentication, which involves sending requests with International Mobile Equipment Identity (IMEI) or Permanent Equipment Identifier (PEI) to determine the authorization status of UE, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in non-3GPP access scenarios, then device access is permitted, but network security is compromised due to inadequate fraud prevention

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that queries the 5G-EIR database to obtain device identity information (IMEI/PEI) and verify authorization status. This intermediary step between the UE and network core enhances security by filtering out fraudulent devices while maintaining legitimate access, resolving the contradiction between security and ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication actions by querying device identity information from the 5G-EIR database before granting full network access. This advance verification of device authorization status prevents fraudulent devices from accessing the network, thereby improving reliability without significantly impacting operational ease

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device identity verification is implemented, then fraudulent access is prevented, but authentication complexity increases

Engineering Contradiction:
Improvefraud preventionVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex identity verification process into a separate, dedicated authentication mechanism that queries the 5G-EIR database independently. By separating this verification step from the main authentication flow, the system achieves robust fraud prevention while keeping the overall authentication process manageable and modular, thus reducing perceived complexity

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If secondary-level authentication is added, then unauthorized devices are blocked, but processing time increases

Engineering Contradiction:
Improveauthorization verificationVSAvoidauthentication duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs the device identity verification as a preliminary action before full authentication completes. By querying the 5G-EIR database in advance and caching device authorization status, the system prevents unauthorized devices early in the process, reducing the time penalty of secondary authentication while maintaining robust authorization verification

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12177212B2Enhanced N17 interface between IMS network and 5G-EIR
Publication Date: 2024.12.24 T MOBILE US INC
  • US12177212B2 patent drawing
  • US12177212B2 patent drawing
  • US12177212B2 patent drawing

AI summary

In a telecommunication network, a Serving Call Session Control Function (S-CSCF) may be coupled with a Fifth Generation (5G) Equipment Identity Register (EIR) via an N17′ interface. In some examples, the S-CSCF can use the N17′ interface instead of a diameter protocol for communicating with the 5G-EIR. The S-CSCF can send a request to the 5G-EIR including a Permanent Equipment Identifier (PEI) associated with a user equipment (UE). In response, the S-CSCF can receive identity data indicative of whether the UE is authorized, not authorized, partially authorized, or unknown. Based on the identity data, the S-CSCF can authenticate a user equipment (UE) accessing a network. In some examples, the S-CSCF may route requests between a 5G-EIR and an EIR. In some examples, this authentication step can comprise a second-level authentication to identify stolen or fraudulent devices and to prevent such devices from accessing the network.