Network Node Authentication Mechanism Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP LTE specifications face challenges in authenticating wireless devices connecting to the core network via multiple access networks with different protocols, as they require distinct authentication endpoints and protocols, complicating the authentication process for 5G networks that need to support various access methods.

Innovation Solution

A network node method that selects and initiates an appropriate authentication mechanism from a plurality of available mechanisms based on the received request, choosing both the authentication method and the network location for the authentication process, enabling seamless authentication across different access networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple authentication endpoints and protocols are used for different access networks, then authentication compatibility across diverse access methods is improved, but system complexity and signaling overhead increase

Engineering Contradiction:
Improveauthentication compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism where a single authentication endpoint can handle multiple access networks (3GPP and non-3GPP) through a unified authentication protocol. The network node is configured to select appropriate authentication mechanisms from a plurality of available mechanisms based on the access network type, enabling one system to serve multiple functions without requiring separate authentication endpoints for each access network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between different access networks and the core network. This intermediary layer selects and translates authentication requests according to the access network type, allowing diverse access methods to communicate with a unified authentication endpoint without exposing the complexity of multiple protocols to the terminal device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple authentication mechanisms are supported, then versatility for different access networks is improved, but signaling complexity increases

Engineering Contradiction:
Improveaccess network supportVSAvoidsignaling complexity
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments the authentication mechanism selection process into distinct phases: receiving the authentication request, determining the access network type, selecting the appropriate authentication mechanism from the plurality of available mechanisms, and initiating the selected mechanism. This segmentation reduces signaling complexity by handling each access network type through a structured, step-by-step process rather than managing all mechanisms simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic selection of authentication mechanisms based on the determined access network type. The network node adaptively chooses from the plurality of authentication mechanisms (such as EPS-AKA for 3GPP access or EAP-based mechanisms for non-3GPP access) according to the specific access network being used, rather than statically configuring all mechanisms. This dynamic approach reduces signaling overhead by activating only the necessary authentication path.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11283798B2Network nodes and methods performed by network node for selecting authentication mechanism
Publication Date: 2022.03.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11283798B2 patent drawing
  • US11283798B2 patent drawing
  • US11283798B2 patent drawing

AI summary

Methods and network nodes of a wireless communications network are disclosed. The network nodes are operable to initiate a plurality of authentication mechanisms. Responsive to receipt of a request for authentication transmitted by a terminal device of the wireless communications network, the network nodes are configured to select an authentication mechanism from the plurality of authentication mechanisms; and are further configured to initiate the selected authentication mechanism to authenticate the terminal device with the wireless communications network.