Network-Triggered UE Authentication for Timely Key Renewal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In current mobile network communication systems, there is no mechanism for the network to trigger an authentication procedure for user equipment (UE), leading to potential service interruptions due to outdated authentication keys and increased security threats.

Innovation Solution

An authentication method and apparatus that enables network elements, such as the UDM, AUSF, and AMF, to coordinate and trigger an authentication procedure for the UE, including sending authentication notification messages and requests to manage authentication keys and counters, ensuring timely key regeneration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE initiates authentication procedure proactively, then authentication can be performed, but the network service may be interrupted due to timing issues and lack of network control

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnetwork service continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a feedback mechanism where the network side (AUSF) sends authentication trigger information to the UDM, which then sends authentication notification messages to the AMF. This closed-loop feedback system ensures the network can reliably control when authentication occurs, preventing service interruptions while maintaining authentication reliability through coordinated network-initiated triggers.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If the network waits for UE to initiate authentication, then UE autonomy is maintained, but security threats increase due to outdated authentication keys

Engineering Contradiction:
ImproveUE authentication autonomyVSAvoidsecurity threats from outdated keys
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by having the network proactively trigger authentication procedures before security issues arise. The AUSF sends trigger information to the UDM, which preemptively initiates authentication notifications to the AMF, ensuring authentication occurs at the optimal time without waiting for UE initiation, thus preventing security threats from outdated keys while maintaining operational efficiency.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If authentication procedure is triggered by network, then service continuity is improved, but network complexity increases due to additional coordination mechanisms

Engineering Contradiction:
Improvenetwork service continuityVSAvoidnetwork coordination complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent uses the UDM as an intermediary component that receives authentication trigger information from the AUSF and sends authentication notification messages to the AMF. This intermediary approach simplifies the overall network architecture by centralizing the authentication coordination function in the UDM, reducing direct complexity between multiple network elements while maintaining service continuity through standardized notification protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250254519A1Authentication method and device
Publication Date: 2025.08.07 BEIJING XIAOMI MOBILE SOFTWARE CO LTD
  • US20250254519A1 patent drawing
  • US20250254519A1 patent drawing
  • US20250254519A1 patent drawing

AI summary

An authentication method includes: receiving an authentication procedure trigger information from an authentication server function (AUSF) network element, in which the authentication procedure trigger information includes an identifier of a user equipment (UE) corresponding to the AUSF network element, and the authentication procedure trigger information indicates the UDM network element to trigger an authentication procedure for the UE; and sending an authentication notification message to an access and mobility management function (AMF) network element, in which the authentication notification message includes the identifier of the UE, and the authentication notification message notifies the AMF network element to perform the authentication procedure for the UE.