Proxy Entity Encapsulates Authentication Signalling for WLAN-PLMN Interworking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Many local access networks do not support sophisticated access control mechanisms, such as IEEE 802.1X, which limits the effectiveness of authentication in interworking systems between wireless local area networks (WLANs) and public land mobile networks (PLMNs).

Innovation Solution

A system that uses a proxy entity to encapsulate authentication signalling messages between a mobile device and an authentication entity using a cryptographic client-server transport layer protocol, such as TLS, allowing secure transfer without requiring specific wireless local access cryptographic procedures, and utilizing existing encapsulation protocols like TLS or RADIUS/Diameter for encapsulation and decapsulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sophisticated access control mechanisms like IEEE 802.1X are used for authentication, then authentication security is improved, but device complexity increases and requires support in local access network elements

Engineering Contradiction:
Improveauthentication securityVSAvoidlocal access network support complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A proxy entity is introduced as an intermediary between the mobile device and the AAA entity. The proxy entity performs protocol conversion and encapsulation, translating authentication messages between different protocols (EAP, RADIUS, Diameter) without requiring the local access network to support complex authentication mechanisms. This mediator approach allows sophisticated authentication to work over simple access networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces complex mechanical authentication mechanisms (IEEE 802.1X requiring local network support) with cryptographic encapsulation protocols (TLS, SSL) that can operate over simpler networks. The proxy entity handles the complex protocol conversion, substituting the need for local network sophistication with remote cryptographic protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If protocol conversion and encapsulation are implemented for authentication, then adaptability to different encapsulation protocols is improved, but device complexity increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidproxy entity complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The proxy entity is designed with multi-functionality to handle multiple encapsulation protocols (TLS, SSL, RADIUS, Diameter) and authentication mechanisms (EAP, SIM-based, USIM-based). This universal approach allows a single proxy implementation to support various protocol combinations, improving adaptability without requiring separate specialized components for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts protocol parameters and message formats based on the capabilities of the mobile device and the requirements of the AAA entity. The proxy entity changes encapsulation parameters (protocol type, encryption methods, message structure) to match the appropriate authentication mechanism, enabling flexible adaptation to different scenarios.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If encapsulation protocols like TLS are used for secure authentication transfer, then authentication security is improved, but ease of operation decreases due to protocol complexity

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication setup complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The proxy entity acts as an intermediary that automatically handles the complex TLS encapsulation and decapsulation processes. Mobile devices and access networks interact through simplified interfaces without needing to manually configure encryption parameters or understand the underlying protocol complexity. The proxy absorbs the operational complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system performs self-configuration and automatic protocol selection. The proxy entity automatically detects the capabilities of connected devices and selects appropriate encapsulation protocols without user intervention. Cryptographic parameters are automatically negotiated and managed, eliminating the need for users to manually configure security settings.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2087689B1Authentication in mobile interworking system
Publication Date: 2021.02.24 TELIASONERA AB
  • EP2087689B1 patent drawingFigure 1~4b
  • EP2087689B1 patent drawingFigure 3

AI summary

The present invention relates to a communications system comprising a radio access network for providing local wireless access for a mobile device (10) and an authentication entity (40) in a public land mobile network, wherein the authentication entity (40) is arranged to authenticate the mobile device (10) accessing the radio access network on the basis of authentication signalling between the authentication entity (40) and the mobile device (10). The system comprises a proxy entity (30) via which transfer of the authentication signalling is arranged, and encapsulated transmission of the authentication signalling to and from the mobile device (10) is arranged in messages of a cryptographic client-server transport layer encapsulation protocol between the mobile device (10) and the proxy entity (30). The system provides encapsulated transfer of the authentication signalling to and from the authentication entity (40) in messages of an AAA client-server protocol between the proxy entity (30) and the authentication entity (40).