NG-RG Location Verification in Fixed-Mobile Convergence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the fixed-mobile convergence architecture, there is no existing solution for verifying the validity of access location information of a next generation-residential gateway (NG-RG) when accessing a 5G mobile core network.

Innovation Solution

An authentication system and method that involves a network device obtaining first and second link information to verify the access location of the NG-RG, and first and second virtual interface information to verify the current service type, ensuring validity based on matching criteria, and deriving keys for different access manners in non-3GPP networks to isolate them.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If location information verification is implemented for NG-RG in fixed-mobile convergence architecture, then security and service reliability are improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improveaccess location validity verificationVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a location verification function (LVF) as an intermediary component within the authentication server. This LVF acts as a mediator that receives location information from the network device, compares it with stored location data, and returns verification results. By isolating the verification logic in a dedicated function, the system maintains security and reliability without significantly increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server is designed to perform multiple functions: standard authentication, location verification, and subscription information management. The location verification function is integrated into the existing authentication framework, allowing the same server to handle both traditional authentication tasks and the new location validation requirement, thereby avoiding the need for separate dedicated verification systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If location information and service type verification are performed, then access control security is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs location verification as part of the initial authentication process before granting access. By verifying location information and service type upfront during the authentication phase, the system ensures security requirements are met before any service activation, preventing the need for additional verification steps during service operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent combines location verification, service type verification, and authentication into a single integrated process. The authentication server simultaneously validates the user's credentials, checks the location information against stored data, and verifies service type authorization, consolidating multiple verification tasks into one unified operation that reduces overall processing time.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3823320B1Authentication method, device, and system
Publication Date: 2023.08.09 HUAWEI TECH CO LTD
  • EP3823320B1 patent drawingFigure 1~2
  • EP3823320B1 patent drawingFigure 3
  • EP3823320B1 patent drawingFigure 4

AI summary

Embodiments of this application provide an authentication method, a device, and a system, to be at least used to verify validity of access location information of an NG-RG in a fixed-mobile convergence architecture. The method includes: A network device receives first link information that is used to represent an access location of a residential gateway, and obtains second link information of the residential gateway. When the first link information matches partial or all information of the second link information, or when the first link information matches partial or all information of one link information of the second link information, the network device verifies validity of the access location of the residential gateway.