Network Access Server Extended Identifier Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of 5G mobile networks, industrial devices with outdated software and vulnerabilities are connected to public networks, posing a risk of manipulation due to the lack of timely patching and the complexity of access authorization management, which increases security and operational risks.

Innovation Solution

A computer-implemented method and network access server that utilize an extended network access identifier to connect network components to a mobile network, incorporating network access restrictions, allowing devices to request specific access parameters and ensuring secure, restricted connections by authenticating and configuring network access based on user profiles and access restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network components with outdated software are connected to public networks, then network connectivity and access are improved, but security risks and vulnerability to manipulation increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network is segmented into public network portions and restricted network slices. Network components are assigned specific network slice identifiers that limit their access to only authorized network segments, preventing exposure to vulnerabilities in public network areas while maintaining necessary connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A network access server acts as an intermediary between network components and the network infrastructure. It authenticates components, assigns appropriate network slice identifiers, and enforces access restrictions, thereby protecting vulnerable devices while enabling network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex access authorization management is implemented, then security control is improved, but operational complexity and management difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidaccess management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Access authorizations and network slice restrictions are predetermined and configured in advance during network component setup. The network access server stores these pre-configured authorization profiles, eliminating the need for complex real-time access management decisions and simplifying operational procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses network slice identifiers as key parameters to automatically determine and enforce access restrictions. By changing from complex policy-based access control to simpler identifier-based slice assignment, the system maintains security control while reducing operational complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11882447B2Computer-implemented method and network access server for connecting a network component to a network with an extended network access identifier
Publication Date: 2024.01.23 SIEMENS AG
  • US11882447B2 patent drawing
  • US11882447B2 patent drawing
  • US11882447B2 patent drawing

AI summary

The invention relates to a computer-implemented method for connecting a network component to a network, in particular a mobile communications network, with an extended network access identifier. The method involves a receiving of the extended network access identifier from the network component via a network access server, wherein the extended network access identifier comprises at least one network access restriction for connecting the network component to the network. The method also involves a receiving of a requested user access profile from a user profile server via the network access server, wherein the user access profile comprises access authorisations for connecting the network component to the network. The network component is authenticated in the network via the network access server, if the received extended network access identifier fulfills thre access authorisations of the received user access profile. Then the network connection of the network component to the network via the network access server is configured by means of the access authorisations of the user access profile once the network component is authenticated. There is also a determining of the network restriction received with the extended network access identifier via the network access server, and a verifying of the configured network connection of the network component to the network via the network access server based on the determined network access restriction. Then the network component is connected to the network via the network access server, once the configured network connection is verified and the configured network connection fulfills the determined network access restrictions.