PIN Authentication Mechanism Selection for Secure 5G IoT Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no technical solution for starting identity authentication for a Personal IoT Network (PIN) element.

Innovation Solution

A method and apparatus for selecting an authentication mechanism for personal IoT devices, involving the exchange of information such as PIN element identifiers, authentication indicators, and supported authentication methods between various network functions, including UE, PEGC, and PEMC, to facilitate secure identity authentication within a PIN.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If no authentication mechanism is implemented for PIN elements, then device complexity is reduced and ease of operation is improved, but communication security and reliability deteriorate

Engineering Contradiction:
Improvecommunication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication management function (AMF) and authentication service function (AUSF) as intermediary components that handle authentication processes centrally. These intermediaries manage the authentication of PIN elements without requiring complex authentication logic in each individual device, thus improving security while keeping device complexity manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into multiple independent functions: authentication management function (AMF), authentication service function (AUSF), and authentication data function (UDM). Each function handles specific aspects of authentication, allowing the system to achieve high security through specialized components while maintaining overall system manageability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple authentication methods are supported for different PIN elements, then adaptability and versatility are improved, but device complexity and information processing requirements increase

Engineering Contradiction:
Improveauthentication method compatibilityVSAvoidauthentication management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework that can handle multiple authentication methods (5G-AKA, EAP-AKA', password-based authentication) through a single standardized interface. The AMF and AUSF functions are designed to be multi-functional, supporting various authentication types without requiring separate processing logic for each method in individual devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses parameter-based configuration to adapt to different authentication methods. By changing authentication parameters (authentication type indicators, security keys, protocol versions) rather than changing the fundamental authentication architecture, the system achieves versatility while maintaining manageable complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250374045A1Method and apparatus for selecting authentication mechanism for personal internet-of-things device, UE, network function, and storage medium
Publication Date: 2025.12.04 BEIJING XIAOMI MOBILE SOFTWARE CO LTD
  • US20250374045A1 patent drawing
  • US20250374045A1 patent drawing
  • US20250374045A1 patent drawing

AI summary

The present disclosure relates to a method and apparatus for selecting an authentication mechanism for a personal Internet-of-things device, a UE, a network function, and a storage medium. The method comprises: receiving at least one of the following information sent by a personal Internet-of-things network (PIN) element: an authentication method name supported by the PIN element, a PIN element identifier, and a PIN element authentication indicator; sending a first message to a first network function to indicate a PIN element authentication process to the first network function, wherein the first message carries at least one of the following information: the PIN element authentication indicator, the authentication method name supported by the PIN element, a subscription concealed identifier (SUCI) or 5G globally unique temporary identifier (5G-GUTI) of a PIN element gateway, and the PIN element identifier. The present disclosure implements the identity authentication of a 5G core network on the PIN element, and improves the communication security of a PIN.