Re-authentication Timer for User Equipment PDN Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 4G wireless networks, there is a security risk as devices can access multiple PDNs without re-authentication, potentially allowing unauthorized users to maintain access indefinitely, posing a threat to network security.

Innovation Solution

Implementing a re-authentication timer mechanism where user equipment (UE) must re-authenticate after a specified period to access additional PDNs, with the Mobility Management Entity (MME) requesting re-authentication information if the timer expires, ensuring secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If re-authentication is required for each PDN access, then network security is improved, but user access efficiency deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiduser access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication when the UE first accesses a PDN, and then maintains this authentication state without requiring re-authentication for subsequent PDN accesses within the same session. This preliminary action establishes security upfront while avoiding repeated authentication overhead during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication state is maintained continuously across multiple PDN accesses without interruption. Once authenticated for a PDN, the UE can access other PDNs without breaking or resetting the authentication state, ensuring continuous useful action (access rights) without repeated authentication steps.

Inventive Principle:
Principle #20Continuity of useful action

2Productivity

If no re-authentication is required, then user access efficiency is improved, but network security deteriorates

Engineering Contradiction:
Improveuser access efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication when the UE first accesses a PDN, and then maintains this authentication state without requiring re-authentication for subsequent PDN accesses within the same session. This preliminary action establishes security upfront while avoiding repeated authentication overhead during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication state is maintained continuously across multiple PDN accesses without interruption. Once authenticated for a PDN, the UE can access other PDNs without breaking or resetting the authentication state, ensuring continuous useful action (access rights) without repeated authentication steps.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If re-authentication timer is implemented, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The MME acts as an intermediary that manages the re-authentication timer and authentication state. Rather than implementing complex re-authentication logic in the UE itself, the MME serves as a mediator that handles timer management and coordinates authentication across PDN accesses, simplifying the UE's implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses feedback from the MME about timer status and authentication state to guide UE behavior. The MME provides feedback information that tells the UE when re-authentication is needed and maintains the authentication state, reducing the complexity of autonomous re-authentication logic in the UE.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9392000B2Re-authentication timer for user equipment
Publication Date: 2016.07.12 VERIZON PATENT & LICENSING INC
  • US9392000B2 patent drawing
  • US9392000B2 patent drawing
  • US9392000B2 patent drawing

AI summary

A device receives, from a user equipment (UE), a first request to access a first packet data network (PDN), and receives authentication information from the UE. The device also grants, based on the first request, the UE access to the first PDN when the authentication information authenticates the UE. The device further receives, from the UE, a second request to access a second PDN, and determines whether a re-authentication timer associated with the second PDN has expired before granting the UE access to the second PDN.