PINE Authentication via PEGC Gateway for Secure 5GS Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Personal IoT network elements (PINE) cannot directly access a 5th generation system (5GS) network, necessitating a method to enable secure authentication and access through a gateway capable device (PEGC) using extensible authentication protocol-authentication and key agreement (EAP-AKA') to facilitate communication within a 3GPP standard network.

Innovation Solution

Perform EAP-AKA' authentication on PINE via a core network device, utilizing a PEGC as a gateway, involving determining expected authentication parameters based on credentials and identifiers, and exchanging authentication information through multiple network elements to establish secure connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If PINE directly accesses 5GS network, then network access capability is improved, but device complexity and security management become problematic since PINE lacks gateway and management capabilities

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidgateway and management capabilities
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces PEGC (Personal IoT Network Element with Gateway Capability) as an intermediary device between PINE and 5GS network. PEGC provides the necessary gateway and management capabilities that PINE lacks, enabling PINE to access the network indirectly through PEGC without requiring PINE itself to have complex gateway functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If EAP-AKA' authentication is performed through PEGC gateway, then secure authentication is achieved, but authentication complexity and signaling overhead increase due to multiple network elements involved

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into distinct phases: PEGC performs initial authentication with the network, then separately handles PINE authentication through EAP-AKA' protocol. This segmentation allows each device to perform specific authentication tasks rather than requiring all devices to handle the complete authentication complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

PEGC acts as an intermediary that relays authentication signals between PINE and the core network. It receives EAP requests from the network, forwards them to PINE, and relays responses back, simplifying the authentication flow from PINE's perspective while maintaining security through the intermediary's involvement.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If PINE connects through second class network to PEGC, then network flexibility is improved, but connection reliability may be affected by additional network interfaces

Engineering Contradiction:
Improvenetwork connection flexibilityVSAvoidconnection reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

PEGC serves as a stable intermediary anchor point that PINE connects to through the second class network. While the second class network interface may vary, PEGC provides a consistent endpoint with guaranteed gateway capabilities, isolating PINE from the variability of different network interfaces while maintaining connection reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250386187A1Authentication method
Publication Date: 2025.12.18 BEIJING XIAOMI MOBILE SOFTWARE CO LTD
  • US20250386187A1 patent drawing
  • US20250386187A1 patent drawing
  • US20250386187A1 patent drawing

AI summary

Embodiments of the present disclosure relate to an authentication method. A core network device performs EAP-AKA′ authentication on a PINE. The PINE is accessed to the first class network by means of a PEGC, and the PINE is connected to the PEGC by means of a second class network.