Network Authentication with Proximal Device Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IoT scenarios with 5G networks, the centralized storage of symmetric keys for terminal devices by Home Subscriber Servers (HSS) leads to heavy load pressure and inefficient network authentication due to long authentication chains, affecting efficiency and reliability.
Innovation Solution
A network authentication method where both network devices and core network devices perform bidirectional authentication, allowing terminal devices to authenticate with proximate devices such as access network gateways, base stations, and MME-AU, reducing the reliance on centralized HSS and improving efficiency and reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized storage of symmetric keys by HSS is used, then network authentication can be implemented, but heavy load pressure on HSS and long authentication chain are caused
Solution Approach 1:
The patent segments the authentication function by introducing an authentication management unit that can operate independently from the centralized HSS. This unit stores authentication parameters locally and can perform authentication operations without always requiring HSS involvement, thereby reducing the load on HSS and shortening the authentication chain while maintaining reliability
Solution Approach 2:
The authentication management unit acts as an intermediary between the terminal device and the HSS. It can handle authentication requests locally when possible, and only communicate with HSS when necessary, thus reducing the frequency of HSS interactions and improving authentication efficiency
2Productivity
If distributed network authentication is used, then authentication efficiency is improved, but the problem of how to perform authentication when both network device and core network device have authentication function arises
Solution Approach 1:
The patent implements a dynamic authentication mechanism where the authentication management unit can adaptively choose between local authentication and HSS-based authentication based on the terminal device's authentication capability. This dynamic approach simplifies the overall process by automatically selecting the most appropriate authentication path without requiring complex manual configuration
Solution Approach 2:
The authentication management unit provides self-service functionality by storing authentication parameters locally and being able to perform authentication operations independently. This reduces reliance on the centralized HSS and allows the system to handle authentication requests efficiently without always requiring core network device involvement
Data Source
AI summary
The disclosure provides a network authentication method, a network device, and a core network device, the network authentication method including: receiving, by a first network device, an access request message sent by a terminal device, where the access request message includes an identity of the terminal device; determining, by the first network device based on the identity of the terminal device, whether to allow authentication on the terminal device; if the first network device does not allow the authentication on the terminal device, sending, by the first network device, the identity of the terminal device to a core network device, so that the core network device performs network authentication based on the identity of the terminal device.


