Non-Cellular Device Authentication via Gateway EAP-TLS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in authenticating terminal devices accessing networks via non-cellular mechanisms, particularly non-3GPP devices, which lack support for Non-Access Stratum (NAS) and require secure connections to ensure data security.

Innovation Solution

A method involving multiple apparatuses to transmit registration and authentication requests to authenticate non-cellular devices, including generating registration requests indicating non-cellular access, performing EAP-TLS authentication, and establishing connections using security information to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-cellular access mechanism is used for terminal device connection, then network access flexibility is improved, but authentication capability deteriorates due to lack of NAS support

Engineering Contradiction:
Improvenetwork access flexibilityVSAvoidauthentication capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the non-cellular terminal device and the cellular network. The gateway performs EAP-TLS authentication on behalf of the terminal device, translating non-NAS authentication requests into NAS-compatible authentication flows that the core network can process, thus enabling authentication capability for non-cellular devices without modifying the terminal device itself

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication function is segmented into separate components: the terminal device connects via non-cellular access, the gateway handles EAP-TLS authentication and NAS message translation, and the core network performs credential verification. This segmentation allows each component to specialize in its function, with the gateway bridging the gap between non-NAS and NAS protocols

Inventive Principle:
Principle #1Segmentation

2Reliability

If EAP-TLS authentication is implemented for non-cellular devices, then security is improved, but device complexity increases due to multiple apparatuses involved

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device is designed with multi-functionality, serving as both a non-cellular access point for terminal devices and a NAS message translator to the core network. It handles EAP-TLS authentication, NAS message translation, and security context management in a single device, reducing the need for separate specialized components and simplifying the overall system architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260067680A1Authentication for device with non-cellular access
Publication Date: 2026.03.05 NOKIA TECHNOLOGIES OY
  • US20260067680A1 patent drawing
  • US20260067680A1 patent drawing
  • US20260067680A1 patent drawing

AI summary

Example embodiments of the present disclosure relate to authentication for device with non-cellular access. A first apparatus transmits, to a second apparatus, a registration request for a third apparatus. The registration request at least indicates that the third apparatus is accessing a network via a non-cellular mechanism. The first apparatus further receives, from the second apparatus, a first message indicating that the third apparatus is authenticated. Based on the receipt of the first message, the first apparatus further transmits security information to a fourth apparatus for establishing a connection between the third and fourth apparatuses. In this way, the third apparatus can be authenticated. In addition, secure connection can be established between the third and fourth apparatuses.