Remote Unit Reauthentication with Dynamic rIKs for Low-Latency TNGF Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G communication systems face delays and complexity in UE reauthentication due to the lack of efficient sharing of re-authentication security context across ER Servers during UE mobility, leading to unnecessary full authentications and increased handover times.
Innovation Solution
Implementing the EAP Re-authentication Protocol (ERP) with dynamic rIKs and key management domains to facilitate secure and efficient re-authentication across Trusted Non-3GPP Gateway Functions (TNGFs), allowing for intra- and inter-TNGF re-authentications without full authentications, thereby reducing latency and complexity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full authentication is performed during UE mobility between TNGFs, then network security is maintained, but handover time and latency increase significantly
Solution Approach 1:
The patent performs preliminary authentication actions by establishing re-authentication security context (including rIK, rMSK, rRK) during initial authentication with the home network. This pre-established context enables rapid re-authentication during mobility events without performing full authentication, thus reducing handover time while maintaining security through pre-computed cryptographic materials
Solution Approach 2:
The patent introduces a re-authentication server as an intermediary component that stores and manages re-authentication security contexts for multiple TNGFs. This intermediary enables seamless handover between TNGFs by mediating the transfer of authentication context, allowing UEs to re-authenticate quickly without involving the home network authentication server for every mobility event
2Productivity
If re-authentication security context is shared across multiple TNGFs, then handover efficiency improves, but system complexity increases
Solution Approach 1:
The patent segments the authentication system into distinct functional components: home network authentication server for initial authentication, re-authentication server for context management, and multiple TNGFs for access. This segmentation allows re-authentication context to be shared efficiently across TNGFs through the re-authentication server without requiring complex peer-to-peer synchronization between all network elements
Solution Approach 2:
The re-authentication server provides universal service to multiple TNGFs by storing and managing re-authentication security contexts that can be accessed by any TNGF in the system. This multi-functional approach allows a single server to serve multiple access points, simplifying the architecture compared to having each TNGF maintain separate authentication contexts
3Reliability
If dynamic rIKs are used for re-authentication, then security against replay attacks is improved, but computational overhead increases
Solution Approach 1:
The patent implements dynamic re-authentication integrity keys (rIKs) that are updated during each re-authentication event. The rIK is derived from the re-authentication master session key (rMSK) and includes a sequence number component, ensuring that each re-authentication uses a fresh key. This dynamic approach prevents replay attacks while keeping computational overhead manageable by reusing the base rMSK and only deriving new rIKs when needed
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for supporting remote unit reauthentication. One apparatus includes a network interface that receives a first authentication message for reauthenticating a remote unit and a processor that verifies a first domain-name. The first domain-name identifies a key management domain name and an associated gateway function holding a reauthentication security context. Here, the first authentication message includes a NAI containing a first username and the first domain-name. The processor validates the first authentication message using at least the first username and generates a second authentication message in response to successfully validating the first authentication message. Via the network interface, the processor responds to the first authentication message by sending the second authentication message.


