RAN Node Authentication for Multiple UEs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Next-generation mobile communication systems, such as 5G, face challenges in providing efficient authentication for multiple user equipment (UEs) with varying security requirements, especially in supporting network slicing and multi-RAT operations, which leads to redundancy and increased latency in authentication processes.

Innovation Solution

An authentication method and apparatus where a radio access network (RAN) node initiates an authentication procedure by transmitting identification information and security messages to a network node, allowing UEs to attach to the network through a specific entity performing authentication functions, thereby reducing redundancy and optimizing authentication procedures based on UE attributes and features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication and security setup are performed for each UE individually, then authentication reliability is improved, but authentication time and system complexity increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines authentication of multiple UEs into a single authentication procedure executed by a base station. Instead of performing separate authentication for each UE, the base station performs one authentication operation that covers multiple UEs simultaneously, thereby reducing authentication time while maintaining security through the authentication vector that includes identifiers for all UEs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication vector serves multiple functions: it authenticates the base station to the network, identifies multiple UEs simultaneously, and enables the network to recognize all UEs as legitimate. This multi-functional approach eliminates the need for separate authentication procedures for each UE.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication procedures are performed for multi-RAT access, then security is improved, but signaling overhead and latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authentication procedures for different RATs (Radio Access Technologies) into a single unified authentication process. The authentication vector contains identifiers for UEs accessing different RATs, allowing the network to authenticate and manage multiple RATs simultaneously without requiring separate authentication signaling for each RAT.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If network slicing is implemented with dedicated core network instances, then service optimization is improved, but security overhead increases

Engineering Contradiction:
Improveservice optimizationVSAvoidsecurity overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by customizing the authentication approach for different network slices. Each network slice can have its own authentication vector with specific identifiers and security parameters tailored to the service requirements. This allows optimized security for each slice without requiring complete security infrastructure duplication, reducing overall security overhead.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10212590B2Method and apparatus for authenticating device in wireless communication system
Publication Date: 2019.02.19 LG ELECTRONICS INC
  • US10212590B2 patent drawing
  • US10212590B2 patent drawing
  • US10212590B2 patent drawing

AI summary

Disclosed are an authentication method performed by a radio access network (RAN) node in a wireless communication system and an apparatus thereof. In the present disclosure, a first message indicating initiation of an authentication procedure of the RAN node for multiple user equipments (UEs) used for a specific purpose to attach to a network is transmitted, an authentication request message including first security information for authenticating the network is received from the first network node, second security information for authenticating the RAN node is transmitted to the first network node, and a complete message indicating completion of the authentication procedure is received from the first network node.