Enhanced N17 Interface for 5G-EIR Secondary Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunication networks face challenges in effectively authenticating user equipment (UE) to prevent fraudulent and stolen devices from accessing the network, particularly in non-3GPP access scenarios like Wi-Fi, where existing authentication methods are inadequate.
Innovation Solution
The implementation of an enhanced N17 interface between the Serving Call Session Control Function (S-CSCF) and the Fifth Generation (5G) Equipment Identity Register (5G-EIR) using a Representational State Transfer (REST) HTTP 2.0 protocol for secondary-level authentication, which involves sending requests with International Mobile Equipment Identity (IMEI) or Permanent Equipment Identifier (PEI) to determine the authorization status of UE, thereby enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used in non-3GPP access scenarios, then device access is permitted, but network security is compromised due to inadequate fraud prevention
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that queries the 5G-EIR database to obtain device identity information (IMEI/PEI) and verify authorization status. This intermediary step between the UE and network core enhances security by filtering out fraudulent devices while maintaining legitimate access, resolving the contradiction between security and ease of operation
Solution Approach 2:
The system performs preliminary authentication actions by querying device identity information from the 5G-EIR database before granting full network access. This advance verification of device authorization status prevents fraudulent devices from accessing the network, thereby improving reliability without significantly impacting operational ease
2Reliability
If device identity verification is implemented, then fraudulent access is prevented, but authentication complexity increases
Solution Approach 1:
The patent extracts the complex identity verification process into a separate, dedicated authentication mechanism that queries the 5G-EIR database independently. By separating this verification step from the main authentication flow, the system achieves robust fraud prevention while keeping the overall authentication process manageable and modular, thus reducing perceived complexity
3Reliability
If secondary-level authentication is added, then unauthorized devices are blocked, but processing time increases
Solution Approach 1:
The system performs the device identity verification as a preliminary action before full authentication completes. By querying the 5G-EIR database in advance and caching device authorization status, the system prevents unauthorized devices early in the process, reducing the time penalty of secondary authentication while maintaining robust authorization verification
Data Source
AI summary
In a telecommunication network, a Serving Call Session Control Function (S-CSCF) may be coupled with a Fifth Generation (5G) Equipment Identity Register (EIR) via an N17′ interface. In some examples, the S-CSCF can use the N17′ interface instead of a diameter protocol for communicating with the 5G-EIR. The S-CSCF can send a request to the 5G-EIR including a Permanent Equipment Identifier (PEI) associated with a user equipment (UE). In response, the S-CSCF can receive identity data indicative of whether the UE is authorized, not authorized, partially authorized, or unknown. Based on the identity data, the S-CSCF can authenticate a user equipment (UE) accessing a network. In some examples, the S-CSCF may route requests between a 5G-EIR and an EIR. In some examples, this authentication step can comprise a second-level authentication to identify stolen or fraudulent devices and to prevent such devices from accessing the network.


