Remote Unit Reauthentication via Key Management Domain

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The EAP Re-authentication Protocol (ERP) currently does not support sharing of re-authentication security context among ER-Servers during UE mobility, leading to unnecessary delays and complexity in UE attachment due to full authentication requirements when moving between different ER-Servers.

Innovation Solution

The introduction of EAP Re-authentication Extensions (ERXs) and the use of key management domains to control sharing of UE's re-authentication security context among TNGFs or TNANs, reducing overhead by using dynamic rIK for integrity protection and avoiding domain-specific root re-authentication key (DSRK) involvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full EAP authentication is performed when UE moves between different ER-Servers, then authentication security is maintained, but attachment delay and network overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidattachment delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication process is segmented into two types: full EAP authentication for initial access or after key expiration, and faster reauthentication using reauthentication security context for mobility between ER-Servers. This segmentation allows the system to maintain security while reducing attachment delay by using the appropriate authentication method based on the scenario.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The reauthentication security context is established during the initial full EAP authentication process and stored in the ER-Server. This preliminary action enables faster reauthentication when the UE moves between ER-Servers, as the security context is already in place and does not require a complete re-authentication process.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If reauthentication security context is shared among multiple ER-Servers, then handover latency is reduced, but security risk increases due to potential key leakage

Engineering Contradiction:
Improvehandover latencyVSAvoidsecurity breach risk
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

Each ER-Server maintains its own reauthentication security context independently, but these contexts are shared across multiple ER-Servers within the same key management domain. This local quality approach ensures that security contexts are available where needed while maintaining proper security boundaries.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses dynamic reauthentication integrity keys (rIK) that are derived from the reauthentication security context and key management domain name. This parameter change approach allows the system to maintain security through dynamic key management while enabling context sharing for low-latency handovers.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If static reauthentication integrity key (rIK) is used for integrity protection, then implementation is simple, but security is compromised due to potential leakage

Engineering Contradiction:
Improveimplementation complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system transitions from static rIK to dynamic rIK that are derived on-demand during reauthentication based on the reauthentication security context and key management domain name. This dynamic approach enhances security by ensuring that the integrity key is fresh and has not been leaked, while the derivation process remains relatively simple.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20230247423A1Supporting remote unit reauthentication
Publication Date: 2023.08.03 LENOVO (SINGAPORE) PTE LTD
  • US20230247423A1 patent drawing
  • US20230247423A1 patent drawing
  • US20230247423A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for supporting remote unit reauthentication. One apparatus apparatus includes a processor and a transceiver that sends a first authentication message to a network function in a mobile communication network and receives a second authentication message from the network function in response to the first authentication message. Here, the first authentication message contains an indicator that the apparatus supports EAP Reauthentication Protocol and the second authentication message contains a key management domain name indicating a group of network functions that can share reauthentication security context. The processor derives reauthentication security context in response to successful authentication with the mobile communication network and locally stores the received key management domain name and the derived reauthentication security context for subsequent reauthentication with the mobile communication network.