Radio Device Authentication via Split Protocol Stack and Key Relay
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Non-3GPP enabled radio communication devices face challenges in accessing 3GPP services without specific hardware, leading to issues with visibility, reachability, and billing in cellular networks, especially in capillary networks where they are not directly connected.
Innovation Solution
A method and device configuration that enables non-3GPP enabled radio communication devices to authenticate with a network using credentials and derive keys for the upper part of the radio protocol stack, allowing communication through a second device with the necessary security protocols, without requiring dedicated hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If non-3GPP enabled radio communication devices connect to the network via capillary networks through another device, then device complexity is reduced and ease of operation is improved, but visibility and reachability in the core network deteriorate
Solution Approach 1:
The patent introduces a capillary gateway as an intermediary device that bridges non-3GPP enabled radio communication devices to the 3GPP core network. The gateway executes the radio protocol stack and forwards signaling between the devices and network, enabling indirect access while maintaining network visibility through the gateway's connection to the core network.
Solution Approach 2:
The patent segments the radio protocol stack execution between the non-3GPP device and the capillary gateway. The device executes the upper part of the protocol stack while the gateway executes the remaining part, allowing the device to operate without full 3GPP hardware while the gateway handles network-facing protocols.
2Device complexity
If non-3GPP enabled radio communication devices use a second device to execute the remaining part of the radio protocol stack, then device complexity is reduced, but network security and integrity may be compromised
Solution Approach 1:
The capillary gateway acts as a trusted intermediary that securely handles key material and authentication. The first radio communication device provides key material to the second device (gateway), which then uses this material to establish secure connections with the core network, maintaining security while reducing device complexity.
Solution Approach 2:
The patent implements preliminary authentication and key derivation before communication begins. The AKA protocol is executed first to authenticate the device and derive key material, which is then securely stored and used by the gateway for subsequent secure communications, ensuring network security is established in advance.
3Reliability
If traditional authentication methods are used for non-3GPP devices, then network security is maintained, but adaptability to different device types deteriorates
Solution Approach 1:
The patent creates a universal access mechanism where the capillary gateway can serve multiple non-3GPP enabled devices with different capabilities. The gateway executes the radio protocol stack and handles authentication for various device types, allowing diverse devices to access the 3GPP core network through a single standardized interface.
Solution Approach 2:
The patent modifies the authentication approach by allowing key material to be provided by the first device and then used by the second device, rather than requiring each device to independently complete full authentication. This parameter change in the authentication flow enables adaptability while maintaining security through the use of derived keys.
Data Source
AI summary
There is provided mechanisms for authenticating a first radio communication device with a network. A method is performed by the first radio communication device. The method comprises obtaining credentials for a network subscription to the network. The method comprises obtaining an upper part of a radio protocol stack, according to which radio protocol stack the first radio communication device is configured to communicate with the network. The method comprises authenticating with the network. The method comprises providing, to a second radio communication device, at least one key, as derived from the credentials during the authenticating, for use by the second radio communication device when executing the remaining part of the radio protocol stack for communication between the second radio communication device and the network.


