Non-Cellular Device Authentication via Gateway EAP-TLS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in authenticating terminal devices accessing networks via non-cellular mechanisms, particularly non-3GPP devices, which lack support for Non-Access Stratum (NAS) and require secure connections to ensure data security.
Innovation Solution
A method involving multiple apparatuses to transmit registration and authentication requests to authenticate non-cellular devices, including generating registration requests indicating non-cellular access, performing EAP-TLS authentication, and establishing connections using security information to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If non-cellular access mechanism is used for terminal device connection, then network access flexibility is improved, but authentication capability deteriorates due to lack of NAS support
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the non-cellular terminal device and the cellular network. The gateway performs EAP-TLS authentication on behalf of the terminal device, translating non-NAS authentication requests into NAS-compatible authentication flows that the core network can process, thus enabling authentication capability for non-cellular devices without modifying the terminal device itself
Solution Approach 2:
The authentication function is segmented into separate components: the terminal device connects via non-cellular access, the gateway handles EAP-TLS authentication and NAS message translation, and the core network performs credential verification. This segmentation allows each component to specialize in its function, with the gateway bridging the gap between non-NAS and NAS protocols
2Reliability
If EAP-TLS authentication is implemented for non-cellular devices, then security is improved, but device complexity increases due to multiple apparatuses involved
Solution Approach 1:
The gateway device is designed with multi-functionality, serving as both a non-cellular access point for terminal devices and a NAS message translator to the core network. It handles EAP-TLS authentication, NAS message translation, and security context management in a single device, reducing the need for separate specialized components and simplifying the overall system architecture
Data Source
AI summary
Example embodiments of the present disclosure relate to authentication for device with non-cellular access. A first apparatus transmits, to a second apparatus, a registration request for a third apparatus. The registration request at least indicates that the third apparatus is accessing a network via a non-cellular mechanism. The first apparatus further receives, from the second apparatus, a first message indicating that the third apparatus is authenticated. Based on the receipt of the first message, the first apparatus further transmits security information to a fourth apparatus for establishing a connection between the third and fourth apparatuses. In this way, the third apparatus can be authenticated. In addition, secure connection can be established between the third and fourth apparatuses.


