Network Authentication Selection for Multi-Network Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge of implementing network authentication for a terminal accessing multiple serving networks through different access types in a wireless communication system is not adequately addressed by current technologies.
Innovation Solution
An authentication method and apparatus that determine a network function to trigger the authentication procedure based on registration information, connection status, and operator policy, enabling the selection of an appropriate access type and network path for authentication, thereby enhancing network security and maintaining service quality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the terminal performs multiple registrations in different serving networks, then the terminal can access multiple serving networks through different access types, but the network authentication procedure becomes complex and uncertain
Solution Approach 1:
The patent segments the authentication procedure by selecting a specific fourth network function (AMF or AUSF) from multiple possible network functions based on the terminal's registration status in different serving networks. This segmentation allows the complex multi-network authentication to be broken down into a standardized single-network authentication flow, resolving the complexity while maintaining multi-network access capability.
Solution Approach 2:
The patent introduces a selection mechanism that acts as an intermediary to determine which network function should trigger the authentication procedure. This intermediary logic (based on registration information, connection status, and operator policy) mediates between the terminal's multi-network presence and the authentication system, selecting the appropriate network function to handle authentication and thus simplifying the overall procedure.
2Reliability
If the network triggers authentication procedure for terminal with multiple registrations, then network security is enhanced, but service quality (roaming and user parameter updates) may be suspended
Solution Approach 1:
The patent applies preliminary action by determining the fourth network function in advance based on registration information and connection status before actually triggering the authentication procedure. This pre-determination ensures that the authentication is triggered through the appropriate network function that can handle it without suspending other services, thus maintaining service quality while enhancing security.
Solution Approach 2:
The patent changes the parameter of network function selection based on different conditions (registration status, connection state, operator policy). By dynamically selecting the appropriate network function (AMF or AUSF) based on these parameters, the system can trigger authentication in a way that preserves service quality - for example, selecting a network function that can perform authentication without interrupting ongoing roaming procedures or user parameter updates.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Provided in the present disclosure are an authentication method and apparatus, a network device, and a computer storage medium. The method may comprise: receiving a first message, the first message being used for triggering an authentication process for a first terminal, and the first terminal being a terminal that separately accesses a first service network and a second service network via different access types; and determining a second network element or a third network element as a fourth network element used for triggering the authentication process, the second network element being a network element of the first service network, and the third network element being a network element of the second service network. The present disclosure can realize network authentication for the terminal in the case of multiple registrations of the terminal in different service networks.