Relay WTRU Secondary Authentication for Secure Layer 3 Connectivity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems lack efficient mechanisms for secondary authentication and authorization (A&A) during link setup and relay operations, particularly in scenarios involving network slice-specific authentication and authorization (NSSAA) and connectivity sessions, which can compromise security and resource management.
Innovation Solution
Implementing a relay WTRU that performs network-controlled secondary A&A and NSSAA procedures, including direct communication requests, traffic filtering, and IP allocation, to ensure secure and authorized connectivity sessions and network access for remote WTRUs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network-controlled secondary A&A and NSSAA procedures are implemented during link setup, then security and resource management are enhanced, but device complexity and processing overhead increase
Solution Approach 1:
The relay WTRU acts as an intermediary between the remote WTRU and the network, forwarding EAP authentication messages and coordinating the secondary A&A process. This mediator role enables security enhancement while distributing processing complexity across multiple entities (relay WTRU, network functions, and remote WTRU) rather than concentrating it all in one device
Solution Approach 2:
The authentication and authorization process is segmented into distinct phases: primary authentication, secondary A&A initiation, EAP message exchange, and authorization completion. Each phase is handled by appropriate network functions and WTRUs, dividing the complex security procedure into manageable segments that can be processed independently
2Reliability
If traffic filtering is configured to discard data traffic until secondary A&A completion, then unauthorized access is prevented, but data transmission delay increases
Solution Approach 1:
The relay WTRU pre-configures traffic filters to discard unauthorized data traffic before secondary A&A completion. This preliminary protective action prevents unauthorized access in advance, and the filter is automatically removed upon successful authentication, allowing legitimate traffic to flow without ongoing delay
Solution Approach 2:
The system implements feedback through the secondary A&A completion status that triggers automatic modification of traffic filter configuration. When authentication succeeds, the relay WTRU receives confirmation and automatically updates the filter settings to allow traffic, creating a dynamic response that balances security with timely data transmission
3Ease of operation
If relay WTRU forwards EAP authentication messages between remote WTRU and network, then transparent authentication is achieved, but message transmission overhead increases
Solution Approach 1:
The relay WTRU utilizes existing multi-functional communication capabilities to forward EAP authentication messages as part of its normal relay operation. By leveraging its established role in message forwarding and network connectivity provision, the relay can handle authentication traffic without requiring dedicated authentication infrastructure, reducing overall system overhead
Data Source
AI summary
A relay wireless transmit/receive unit (WTRU) may receive a direct communication request (DCR) from a remote WTRU requesting connectivity service (e.g., connectivity session parameters such as single-network slice selection assistance (S-NSSA!), data network name (DNN)), The relay may determine that the connectivity session for the service is subject to a secondary authentication and authorization (A&A), based on an indication associated with the connectivity session if already established and/or an indication associated DN from relay proximity service (ProSe) configuration. Based on the determination, the relay may trigger a network-controlled authorization for the remote WTRU. The relay WTRU may send a direct communication accept (DCA) message including a pending secondary A&A. and configure a traffic filter associated with the connection (e.g., a PC5 link) to discard data traffic from the remote WTRU until a successful completion of the secondary A&A.


