TNGF Reauthentication Using NAI Intent Signaling at TNAP Reconnect
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 3GPP standards fail to distinguish between UE requests for NAS procedures and TNGF reauthentication, leading to unnecessary signaling and processing load in the 5GC network when UEs reconnect with a different TNAP without initiating NAS messages.
Innovation Solution
The UE uses a specific NAI to signal its intent, setting a reauthentication identifier (Reauth-ID) when reconnecting with the TNGF, enabling a mutual reauthentication process without involving the 5GC, using EAP sessions with vendor-defined methods like EAP-5G to authenticate the TNGF.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If the UE uses a specific NAI with Reauth-ID to signal reauthentication intent, then the TNGF can perform mutual reauthentication without involving the 5GC, but the UE and TNGF must implement vendor-defined EAP methods (e.g., EAP-5G) for authentication
Solution Approach 1:
The authentication process is segmented into two independent parts: (1) NAI-based intent signaling to distinguish reauthentication from NAS procedure initiation, and (2) vendor-defined EAP methods (e.g., EAP-5G) for actual authentication. This segmentation allows the 5GC to be excluded from reauthentication while maintaining security through specialized authentication protocols.
Solution Approach 2:
The NAI with Reauth-ID acts as an intermediary signal between the UE and TNGF, enabling the TNGF to identify reauthentication requests and initiate the appropriate EAP-based mutual authentication process without involving the 5GC core network.
2Ease of operation
If the TNGF sends EAP start packet to initiate NAS signaling procedure, then the UE can send NAS messages to the mobile communication network, but unnecessary signaling is generated when UEs reconnect without initiating NAS messages
Solution Approach 1:
The UE performs preliminary action by setting the Reauth-ID in the NAI before initiating EAP session, which pre-signals the TNGF's intent to perform reauthentication only. This prevents the TNGF from mistakenly sending EAP start packets that would trigger unnecessary NAS signaling and processing in the 5GC.
Solution Approach 2:
The TNGF uses feedback from the NAI content (specifically the Reauth-ID) to determine the appropriate response: sending EAP challenge packets for mutual authentication when Reauth-ID is present, or EAP start packets only when NAS signaling is actually required, thereby avoiding unnecessary 5GC involvement.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for supporting TNGF reauthentication. One apparatus includes a processor that establishes connectivity with a first access point in a non-3GPP access network. The processor sends a first EAP message containing a NAI. If the NAI indicates a request to reauthenticate with a gateway function in the non-3GPP access network, then the processor receives a first EAP challenge packet used to authenticate the gateway function. If the NAI indicates a request to initiate a NAS signaling procedure with a mobile communication network, then the processor receives an EAP start packet. Here, the EAP start packet triggers the processor to send a first NAS message to the mobile communication network. The processor completes an EAP session initiated by one of the first EAP challenge packet and the EAP start packet.


