Reversed 5G Mutual Authentication for Satellite Store-and-Forward

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing 5G authentication flow is not suitable for store and forward (S&F) use cases, as it assumes continuous connectivity between the User Equipment (UE) and the core network, which is not guaranteed in S&F scenarios.

Innovation Solution

A mutual authentication method is proposed that reverses the authentication flow, initiating it from the User Equipment (UE) side instead of the network side, while maintaining the predefined authentication scheme. This method includes generating a random authentication key hierarchy, creating an authentication vector, protecting user plane data, and forwarding it through the satellite to the serving ground network for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the existing 5G authentication flow is used, then continuous connectivity between UE and core network is assumed, but store and forward operation with intermittent satellite connectivity cannot be supported

Engineering Contradiction:
Improveadaptability to store and forward operationVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent inverts the traditional authentication flow by having the UE initiate authentication instead of the network. The UE generates an authentication vector containing a random challenge and expected result, sends it to the network, and the network verifies it. This reversal allows authentication to proceed even when the UE is disconnected from the network, as the authentication credentials can be stored and forwarded by the satellite when connectivity is restored.

Inventive Principle:
Principle #13The other way round (Inversion)

2Ease of operation

If authentication is initiated from network side, then standardized authentication scheme is followed, but connection discontinuity in satellite coverage cannot be coped with

Engineering Contradiction:
Improveease of authentication operationVSAvoidadaptability to intermittent connectivity
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by having the UE generate the authentication vector (including random challenge, expected result, and authentication token) in advance before actual authentication is needed. This pre-generated authentication credentials can be stored locally and later transmitted to the network when satellite connectivity is available, eliminating the need for real-time network interaction during authentication initiation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional authentication flow is used, then security verification is performed, but number of satellite connections is increased

Engineering Contradiction:
Improvesecurity verificationVSAvoidnumber of satellite connections
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the authentication process with data transmission by incorporating the authentication vector and user plane data into the same satellite communication session. The UE sends both authentication credentials and data payload together in one transmission, and the network processes both simultaneously, reducing the number of separate satellite connections required compared to traditional separate authentication and data transmission phases.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4572233A1Method to perform a mutual authentication
Publication Date: 2025.06.18 THALES DIS FRANCE SA
  • EP4572233A1 patent drawingFigure 1~2
  • EP4572233A1 patent drawingFigure 3
  • EP4572233A1 patent drawing

AI summary

The invention relates to a method to perform a mutual authentication according to a predefined authentication scheme between a User Equipment UE and a 5G communication serving ground network in a context where the UE having a Subscription Permanent Identifier (SUPI) registered at a home network is connected via a non-geostationary satellite access in store and forward operation. The invention proposes to reverse the authentication flow by initiating the authentication flow on the UE side.