Residential Gateway Authentication for Non-3GPP 5G Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in authenticating non-3GPP devices behind a residential gateway with a 5G Call Network, as they lack efficient methods to verify and connect these devices to a 5G Core Network, especially when using non-5G compatible devices and untrusted access networks.

Innovation Solution

The system employs a computing device within the 5G Core Network that receives authentication requests from non-3GPP devices, selects an appropriate authentication method, transmits challenge messages, verifies responses, and communicates authentication results, utilizing entities like the Unified Data Management function and Authentication Server to manage network access and authentication for both 3GPP and non-3GPP devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If non-3GPP devices connect through a residential gateway to the 5G Core Network, then network coverage and accessibility are improved, but authentication complexity and security verification difficulty increase

Engineering Contradiction:
Improvenetwork coverageVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a residential gateway as an intermediary component that sits between non-3GPP devices and the 5G Core Network. The gateway performs local authentication and protocol conversion, mediating the complex interaction between diverse non-3GPP devices and the 5G core network authentication mechanisms, thereby reducing the burden on individual devices while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into multiple stages: local authentication at the residential gateway level, followed by core network authentication. This segmentation allows the system to handle different authentication requirements at appropriate levels, reducing overall complexity by breaking down the monolithic authentication process into manageable components

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple authentication methods are supported for different device types, then system versatility is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improveauthentication method supportVSAvoidconfiguration difficulty
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system dynamically selects authentication methods based on device type, capabilities, and network conditions. The residential gateway and core network automatically adapt the authentication approach (e.g., EAP-AKA', EAP-TLS, or other methods) without requiring manual configuration, making the system versatile while keeping device complexity low through automated method selection

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The residential gateway is designed with universal functionality to support multiple authentication protocols and device types through a single platform. This multi-functional gateway can handle 3GPP devices, non-3GPP devices, and various authentication methods, eliminating the need for separate specialized devices for each authentication scenario

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If authentication verification is performed at the core network level, then security is improved, but authentication time and network latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The residential gateway performs preliminary authentication verification before devices connect to the 5G Core Network. This preliminary check filters out unauthorized devices early, allowing the core network to focus verification resources on authenticated devices, thereby reducing overall authentication time while maintaining security through layered verification

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If non-5G compatible devices are allowed to connect, then device compatibility is improved, but network security and protocol compliance challenges increase

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The residential gateway acts as a security intermediary that enforces protocol compliance and security policies for non-5G compatible devices. It translates and validates device communications before allowing access to the 5G Core Network, ensuring that incompatible devices meet security requirements without requiring modifications to the core network

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts authentication parameters, security policies, and protocol configurations based on device compatibility assessments. For non-5G compatible devices, the gateway modifies authentication parameters and applies appropriate security policies to ensure compliance while maintaining connectivity, thereby managing security risks through adaptive parameter control

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240114338A1Systems and methods for authentication of non-3GPP devices behind a residential gateway
Publication Date: 2024.04.04 CABLE TELEVISION LAB INC
  • US20240114338A1 patent drawing
  • US20240114338A1 patent drawing
  • US20240114338A1 patent drawing

AI summary

A system for authenticating a core network includes a computing device including at least one processor in communication with at least one memory device. The at least one memory device stores a plurality of instructions, which when executed cause the processor to receive an authentication request message routed from a non-3GPP device. The executed instructions also cause the processor to transfer the authentication request message to a unified data management function. The executed instructions further cause the processor to select an authentication method based upon the authentication request. In addition, the executed instructions cause the processor to transmit an authentication challenge message to the non-3GPP device. Moreover, the executed instructions cause the processor to receive the authentication response from the non-3GPP device. Furthermore, the executed instructions cause the processor to verify the authentication response. Additionally, the executed instructions cause the processor to transmit the authentication result to the non-3GPP device.