Secure NAS Channel for 5G User Credential Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication procedures in 5G mobile communication systems often rely on unsecure channels for exchanging authentication-related signaling between users and authentication service providers.

Innovation Solution

The proposed method involves transmitting user credentials, such as name information, mobile phone number, and date of birth, over a secure Non-Access Stratum (NAS) channel, following primary authentication by the User Equipment (UE) and the network, to facilitate secure user authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user credentials are transmitted over unsecure channels for authentication, then the authentication process can be completed, but security and protection of user credentials deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidcredential exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the NAS (Non-Access Stratum) layer as an intermediary secure channel between the UE and authentication service provider. This intermediary layer provides encrypted communication that protects credentials during transmission, resolving the contradiction by enabling secure authentication without exposing credentials to harmful factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security parameter of the communication channel from unsecure to secure by utilizing NAS layer encryption. This parameter change transforms the transmission medium to protect credentials while maintaining authentication functionality, directly addressing the security improvement need.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If primary authentication is performed before credential transmission, then authentication security is improved, but the authentication process complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs primary authentication as a preliminary action before credential transmission. This preliminary authentication establishes security context and trust relationships in advance, enabling subsequent credential transmissions to occur over secure channels without requiring complex authentication procedures during the actual credential exchange.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process is segmented into distinct phases: primary authentication phase (establishing security context) and credential transmission phase (using secure NAS channel). This segmentation allows each phase to be optimized independently, reducing overall complexity while maintaining high security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250142327A1Method and apparatus for authenticating users in wireless communication system
Publication Date: 2025.05.01 SAMSUNG ELECTRONICS CO LTD
  • US20250142327A1 patent drawing
  • US20250142327A1 patent drawing
  • US20250142327A1 patent drawing

AI summary

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. According to an embodiment of the disclosure, a method performed by a user equipment (UE) comprises transmitting, to a UDM (unified data management), a first message for credentials for the UE, the credentials for the UE including at least one of name information, a mobile phone number, and a date of birth. The method comprises receiving, from the UDM, a second message indicating authentication success, wherein the second message includes a user ID corresponding to the credentials for the UE. The method comprises receiving, from an AMF (access and mobility management function), a third message to trigger local authentication of the UE. The method comprises performing the local authentication for the UE based on the second message and the third message.