Proxy Entity Encapsulates Authentication Signalling for WLAN-PLMN Interworking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Many local access networks do not support sophisticated access control mechanisms, such as IEEE 802.1X, which limits the effectiveness of authentication in interworking systems between wireless local area networks (WLANs) and public land mobile networks (PLMNs).
Innovation Solution
A system that uses a proxy entity to encapsulate authentication signalling messages between a mobile device and an authentication entity using a cryptographic client-server transport layer protocol, such as TLS, allowing secure transfer without requiring specific wireless local access cryptographic procedures, and utilizing existing encapsulation protocols like TLS or RADIUS/Diameter for encapsulation and decapsulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sophisticated access control mechanisms like IEEE 802.1X are used for authentication, then authentication security is improved, but device complexity increases and requires support in local access network elements
Solution Approach 1:
A proxy entity is introduced as an intermediary between the mobile device and the AAA entity. The proxy entity performs protocol conversion and encapsulation, translating authentication messages between different protocols (EAP, RADIUS, Diameter) without requiring the local access network to support complex authentication mechanisms. This mediator approach allows sophisticated authentication to work over simple access networks.
Solution Approach 2:
The patent replaces complex mechanical authentication mechanisms (IEEE 802.1X requiring local network support) with cryptographic encapsulation protocols (TLS, SSL) that can operate over simpler networks. The proxy entity handles the complex protocol conversion, substituting the need for local network sophistication with remote cryptographic protection.
2Adaptability or versatility
If protocol conversion and encapsulation are implemented for authentication, then adaptability to different encapsulation protocols is improved, but device complexity increases
Solution Approach 1:
The proxy entity is designed with multi-functionality to handle multiple encapsulation protocols (TLS, SSL, RADIUS, Diameter) and authentication mechanisms (EAP, SIM-based, USIM-based). This universal approach allows a single proxy implementation to support various protocol combinations, improving adaptability without requiring separate specialized components for each protocol.
Solution Approach 2:
The system dynamically adjusts protocol parameters and message formats based on the capabilities of the mobile device and the requirements of the AAA entity. The proxy entity changes encapsulation parameters (protocol type, encryption methods, message structure) to match the appropriate authentication mechanism, enabling flexible adaptation to different scenarios.
3Reliability
If encapsulation protocols like TLS are used for secure authentication transfer, then authentication security is improved, but ease of operation decreases due to protocol complexity
Solution Approach 1:
The proxy entity acts as an intermediary that automatically handles the complex TLS encapsulation and decapsulation processes. Mobile devices and access networks interact through simplified interfaces without needing to manually configure encryption parameters or understand the underlying protocol complexity. The proxy absorbs the operational complexity while maintaining security.
Solution Approach 2:
The authentication system performs self-configuration and automatic protocol selection. The proxy entity automatically detects the capabilities of connected devices and selects appropriate encapsulation protocols without user intervention. Cryptographic parameters are automatically negotiated and managed, eliminating the need for users to manually configure security settings.
Data Source
Figure 1~4b
Figure 3
AI summary
The present invention relates to a communications system comprising a radio access network for providing local wireless access for a mobile device (10) and an authentication entity (40) in a public land mobile network, wherein the authentication entity (40) is arranged to authenticate the mobile device (10) accessing the radio access network on the basis of authentication signalling between the authentication entity (40) and the mobile device (10). The system comprises a proxy entity (30) via which transfer of the authentication signalling is arranged, and encapsulated transmission of the authentication signalling to and from the mobile device (10) is arranged in messages of a cryptographic client-server transport layer encapsulation protocol between the mobile device (10) and the proxy entity (30). The system provides encapsulated transfer of the authentication signalling to and from the authentication entity (40) in messages of an AAA client-server protocol between the proxy entity (30) and the authentication entity (40).