Non-3GPP Network Access Authentication Using Retained Security Context
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing network access authentication procedures for user equipment (UE) in 5G non-3GPP networks are complex and time-consuming, requiring repeated authentication processes, which negatively impact user experience due to long authentication waiting times.
Innovation Solution
The method involves using retained security context information from previous network access to generate authentication codes and keys, allowing UE to perform faster network access authentication by reducing the number of steps in the authentication procedure through interactions with the non-3GPP interworking function network element (N3IWF) and access and mobility management function (AMF) elements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the UE performs complete network access authentication procedure with N3IWF, AMF, and AUSF, then security authentication is ensured, but authentication time increases and user experience deteriorates
Solution Approach 1:
The patent applies preliminary action by performing authentication procedures during initial network access, establishing security context information that can be reused for subsequent accesses. The UE and network elements (AMF, AUSF) complete the full authentication process in advance, storing authentication results and security parameters that eliminate the need for repeated authentication when the UE reconnects to the network.
2Reliability
If the UE repeats the network access authentication procedure for each non-3GPP access, then security is maintained, but the number of authentication steps increases and complexity rises
Solution Approach 1:
The patent extracts the essential authentication function by separating the security verification step from the complete authentication procedure. Instead of repeating all authentication steps (UE-N3IWF-AMF-AUSF interaction), the system extracts and reuses only the critical security verification using stored context information, significantly reducing the number of signaling messages and procedural steps while maintaining security assurance.
3Productivity
If the UE uses retained security context information for authentication, then authentication steps are reduced and access speed improves, but the number of interactions with network elements decreases potentially affecting security verification
Solution Approach 1:
The patent uses the N3IWF as an intermediary that mediates between the UE's use of retained security context information and the network's security verification requirements. The N3IWF receives the authentication request from the UE, validates the stored context information, and coordinates with the AMF and AUSF to perform necessary security checks, thereby enabling fast re-access while maintaining rigorous security verification through the intermediary's coordination role.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention disclose a method and a system for performing network access authentication based on a non-3GPP network, and a related device. The method includes: sending, by UE, a first request message to an N3IWF, where the first request message carries a first authentication code, AMF indication information, and key identifier information, the first authentication code is used by the N3IWF to perform security authentication on the UE, and the key identifier information is used to obtain the first security key; receiving a first response message returned by the N3IWF based on the first request message, where the first response carries a second authentication code, and the first response message is used to indicate that the security authentication performed by the N3IWF on the UE succeeds; and performing, by the UE, integrity verification on the second authentication code, where mutual security authentication can be performed between the UE and the N3IWF after the verification succeeds. According to the present invention, after the UE successfully accesses a network last time, the UE can quickly access the network based on non-3GPP.