Reauthentication in Non-Seamless WLAN Offload via NRF Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security management in 5G communication networks faces challenges with user equipment authentication, particularly in non-seamless wireless local area network offload access environments, where existing technologies lack defined procedures for reauthentication and revocation.

Innovation Solution

The implementation of a method involving a first network entity receiving and sending requests for reauthentication or revocation of user equipment in a wireless local area network access environment, utilizing a non-seamless wireless local area network offload function and unified data management to manage user equipment context, enabling stateful operations for reauthentication and revocation procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If non-seamless WLAN offload access is implemented to improve network efficiency and subscriber convenience, then security management becomes more complex and challenging

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the security management functionality by introducing a dedicated Network Repository Function (NRF) that separately handles user equipment context information. This segmentation allows the WLAN offload function to operate independently while the NRF manages authentication and revocation requests, reducing overall system complexity despite the added security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces the NRF as an intermediary component between the WLAN offload function and the user equipment. The NRF mediates reauthentication and revocation requests by maintaining UE context information and coordinating with the WLAN access network, thereby simplifying the security management architecture while enabling robust security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If existing authentication technologies are used in non-seamless WLAN offload environments, then implementation is simpler, but defined procedures for reauthentication and revocation are lacking

Engineering Contradiction:
Improveimplementation simplicityVSAvoidauthentication procedure completeness
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies preliminary action by having the NRF pre-store user equipment context information before authentication is needed. This pre-positioning of critical data enables rapid reauthentication and revocation operations without requiring complex real-time queries, thus maintaining implementation simplicity while ensuring complete authentication procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the NRF receives reauthentication and revocation requests from the WLAN offload function, processes them using stored UE context, and returns authentication results. This closed-loop feedback ensures complete and reliable authentication procedures while maintaining straightforward implementation through well-defined request-response interactions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240224028A1Reauthentication and revocation in non-seamless wireless local area network offload access environment
Publication Date: 2024.07.04 NOKIA TECHNOLOGIES OY
  • US20240224028A1 patent drawing
  • US20240224028A1 patent drawing
  • US20240224028A1 patent drawing

AI summary

Techniques are disclosed for managing reauthentication and revocation in a communication network environment. In one example, a method comprises receiving, at a first network entity (e.g., an NSWOF), a request from a second network entity (e.g., a UDM) of a communication network to which user equipment is subscribed (e.g., HN), wherein the received request is for a reauthentication or a revocation of the user equipment in accordance with wireless local area network access. The first network entity identifies the user equipment based on information about the user equipment (e.g., UE context) previously stored by the first network entity. The first network entity sends at least a portion of the received request toward the user equipment, and then continues to participate in the reauthorization or revocation based on the request.