Secure 5G Tunneling for SIM-Less Non-3GPP Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Devices lacking SIM or eSIM capabilities, such as IoT devices, are unable to effectively connect to 5G core networks, and traditional security methods like VPNs are insufficient, limiting connectivity and usability, especially for non-3GPP UEs.
Innovation Solution
Implementing a universal 3GPP-based secure tunnel-as-a-service that uses a cloud-native non-3GPP Interworking Function (N3IWF) to establish secure tunnels within non-3GPP networks, enabling devices to connect to 5G core networks through enhanced security mechanisms, including IP traffic inspection and DDOS attack prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional VPN-based security methods are used to connect devices to the network, then security is provided, but connectivity is limited and usability is reduced for non-3GPP devices
Solution Approach 1:
The patent introduces a Non-3GPP Interworking Function (N3IWF) as an intermediary component that enables non-3GPP devices to connect to the 5G core network. The N3IWF acts as a mediator between devices using non-3GPP protocols (like Wi-Fi) and the 5G core network, translating and bridging the communication protocols while maintaining security. This resolves the contradiction by providing both security (through controlled access) and connectivity (through protocol translation)
Solution Approach 2:
The patent creates a universal access mechanism that allows both 3GPP and non-3GPP devices to connect to the same 5G core network through a unified interface. The N3IWF provides multi-functional capability by supporting multiple access types (3GPP cellular and non-3GPP wireless) through a single network entry point, enabling diverse devices with different protocol capabilities to access network services uniformly
2Stability of the object's composition
If 3GPP UEs are limited to two N1 signaling links (one 3GPP link and one non-3GPP link), then network control is maintained, but efficiency and effectiveness of attachment are reduced
Solution Approach 1:
The patent segments the N1 signaling functionality by introducing a separate N3IWF component that handles non-3GPP access signaling independently. Instead of limiting devices to a single N1 link, the segmentation allows multiple N1 signaling links to be established through different access types (3GPP and non-3GPP) via the N3IWF, improving attachment efficiency while maintaining network control through centralized management
3Device complexity
If non-3GPP UEs are unable to establish multiple N1 links, then network simplicity is maintained, but connectivity and service access are limited
Solution Approach 1:
The N3IWF serves as an intermediary that abstracts the complexity of multiple N1 link management from the UE. The intermediary handles the establishment and management of multiple N1 signaling links between non-3GPP UEs and the 5G core network, allowing UEs to achieve enhanced connectivity without increasing their own complexity. The N3IWF manages the multiplexing and routing of signaling messages across multiple links
4Reliability
If conventional security gateways are deployed on premise by a wireless operator, then security is provided for connected devices, but connectivity is limited to devices connecting to that operator's core network
Solution Approach 1:
The patent creates a universal security gateway function within the 5G core network that provides security services across multiple operator networks. The N3IWF implements security mechanisms (authentication, encryption, integrity protection) that are applicable to both 3GPP and non-3GPP access types and can serve devices from different operators. This universal security framework enables cross-operator connectivity while maintaining robust security through standardized security procedures
Data Source
AI summary
An apparatus establishes a secure tunnel within a non-3GPP network to connect to a 5G core network (5GCN) via a non-3GPP Interworking Function (N3IWF) service of the 5GCN. The apparatus lacks subscriber identity module (SIM) capability and eSIM capability. The non-3GPP network connects to the 5GCN using a backhaul network that lacks a radio access network (RAN). The apparatus includes a connectivity stack that configures the apparatus to establish the secure tunnel. The connectivity stack includes a control plane layer and a user plane layer. The apparatus sends a registration request to the 5GCN via the established secure tunnel. The apparatus performs a security handshake with the 5GCN via the N3IWF service. The security handshake includes an exchange of security parameters between the apparatus and the N3IWF service. The apparatus receives a message indicating that registration of the apparatus with the 5GCN over the non-3GPP network is complete.


