Remote Unit Reauthentication with Dynamic rIKs for Low-Latency TNGF Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G communication systems face delays and complexity in UE reauthentication due to the lack of efficient sharing of re-authentication security context across ER Servers during UE mobility, leading to unnecessary full authentications and increased handover times.

Innovation Solution

Implementing the EAP Re-authentication Protocol (ERP) with dynamic rIKs and key management domains to facilitate secure and efficient re-authentication across Trusted Non-3GPP Gateway Functions (TNGFs), allowing for intra- and inter-TNGF re-authentications without full authentications, thereby reducing latency and complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full authentication is performed during UE mobility between TNGFs, then network security is maintained, but handover time and latency increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidhandover time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary authentication actions by establishing re-authentication security context (including rIK, rMSK, rRK) during initial authentication with the home network. This pre-established context enables rapid re-authentication during mobility events without performing full authentication, thus reducing handover time while maintaining security through pre-computed cryptographic materials

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a re-authentication server as an intermediary component that stores and manages re-authentication security contexts for multiple TNGFs. This intermediary enables seamless handover between TNGFs by mediating the transfer of authentication context, allowing UEs to re-authenticate quickly without involving the home network authentication server for every mobility event

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If re-authentication security context is shared across multiple TNGFs, then handover efficiency improves, but system complexity increases

Engineering Contradiction:
Improvehandover efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional components: home network authentication server for initial authentication, re-authentication server for context management, and multiple TNGFs for access. This segmentation allows re-authentication context to be shared efficiently across TNGFs through the re-authentication server without requiring complex peer-to-peer synchronization between all network elements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The re-authentication server provides universal service to multiple TNGFs by storing and managing re-authentication security contexts that can be accessed by any TNGF in the system. This multi-functional approach allows a single server to serve multiple access points, simplifying the architecture compared to having each TNGF maintain separate authentication contexts

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dynamic rIKs are used for re-authentication, then security against replay attacks is improved, but computational overhead increases

Engineering Contradiction:
Improvesecurity against replay attacksVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic re-authentication integrity keys (rIKs) that are updated during each re-authentication event. The rIK is derived from the re-authentication master session key (rMSK) and includes a sequence number component, ensuring that each re-authentication uses a fresh key. This dynamic approach prevents replay attacks while keeping computational overhead manageable by reusing the base rMSK and only deriving new rIKs when needed

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12362940B2Supporting remote unit reauthentication
Publication Date: 2025.07.15 LENOVO (SINGAPORE) PTE LTD
  • US12362940B2 patent drawing
  • US12362940B2 patent drawing
  • US12362940B2 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for supporting remote unit reauthentication. One apparatus includes a network interface that receives a first authentication message for reauthenticating a remote unit and a processor that verifies a first domain-name. The first domain-name identifies a key management domain name and an associated gateway function holding a reauthentication security context. Here, the first authentication message includes a NAI containing a first username and the first domain-name. The processor validates the first authentication message using at least the first username and generates a second authentication message in response to successfully validating the first authentication message. Via the network interface, the processor responds to the first authentication message by sending the second authentication message.