Service Indicator Container for Targeted Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication systems face challenges in securely providing multiple services to user equipment (UEs) without authentication and authorization, leading to potential security compromises and restricted functionality due to undefined or underdeveloped techniques for facilitating authentication and authorization (AA) for various services beyond aerial services.
Innovation Solution
The system implements a method where a UE requests AA for a service by transmitting a container with an indicator of the service to a session management function (SMF), which selects a network exposure function (NEF) and application function (AF) supporting AA, enabling secure access to multiple services by authenticating and authorizing the UE.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication and authorization techniques are not implemented for multiple services, then system complexity is reduced and ease of operation is improved, but network security is compromised
Solution Approach 1:
The patent introduces a service identifier as an intermediary element that enables targeted authentication and authorization without requiring complex service-specific procedures. The service identifier acts as a mediator between the UE and the authentication system, allowing the network to route authentication requests to appropriate network functions based on the service type, thereby maintaining security while avoiding excessive complexity
Solution Approach 2:
The patent creates a universal authentication and authorization framework that can handle multiple different services through a common procedure. By defining a generic AA mechanism that works across various services (aerial, terrestrial, non-terrestrial, etc.), the system achieves broad applicability without requiring separate complex authentication systems for each service type
2Reliability
If service-specific authentication and authorization procedures are defined for each service type, then network security is improved and service-specific requirements are met, but system complexity and difficulty of implementation increase
Solution Approach 1:
The patent segments the authentication and authorization process into distinct modular components: service identifier indication, network function selection based on service type, and service-specific AA procedures. This segmentation allows each service type to have its own tailored procedure while maintaining a unified overall framework, making implementation easier compared to creating entirely separate systems for each service
3Reliability
If authentication and authorization procedures are implemented for multiple services, then network security is improved, but the overhead and loss of time for authentication processes increase
Solution Approach 1:
The patent implements preliminary action by having UEs indicate their desired service type (aerial, terrestrial, non-terrestrial) in advance before the actual authentication and authorization process begins. The network can then pre-select the appropriate network function and prepare the corresponding AA procedure, reducing the time required during the actual authentication phase by having critical decisions made beforehand
Data Source
AI summary
Methods, systems, and devices for wireless communications are described. The described techniques support authentication and authorization (AA) for various services provided by a network and supported by a user equipment (UE). A UE may transmit a container to a first network entity requesting AA for a first service. The container may include an indicator of the first service, and the indicator may indicate or distinguish the first service from multiple services. The first network entity may query a third network entity based on the indicator of the first service to discover a second network entity supporting AA for the first service. The first network entity may then transmit an indicator of the first service to the second network entity, and the second network entity may select a fourth network entity supporting AA for the first service.


