SMF Secondary Authentication via EAP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication networks face challenges in supporting alternative authentication methods due to strict recommendations and requirements on transport networks, particularly when relying on Internet Protocol (IP) connectivity, which jeopardizes the separation between the control plane and user plane.

Innovation Solution

The implementation of an Extensible Authentication Protocol (EAP) between user equipment and a control plane function, such as a Session Management Function (SMF), enables secondary authentication that is not reliant on IP connectivity and maintains separation between the control plane and user plane, supporting various authentication methods and credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IP connectivity is used for alternative authentication methods, then authentication flexibility is improved, but separation between control plane and user plane deteriorates

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidcontrol plane separation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into two distinct planes: control plane functions (SMF) handle authentication signaling and decision-making, while user plane functions handle data traffic. This segmentation allows alternative authentication methods to be implemented without compromising control plane separation, as authentication messages are exchanged through dedicated control plane interfaces rather than relying on IP connectivity in the user plane.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Session Management Function (SMF) acts as an intermediary between the user equipment and the authentication server. The SMF receives authentication requests, forwards them through appropriate interfaces, and manages the authentication flow without requiring direct IP connectivity between endpoints. This intermediary role preserves control plane separation while enabling flexible authentication methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If alternative authentication methods are supported, then use case diversity is improved, but transport network requirements become more stringent

Engineering Contradiction:
Improveuse case diversityVSAvoidtransport network requirements
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a universal authentication framework based on EAP that can accommodate multiple authentication methods (EAP-TLS, EAP-AKA, EAP-PEAP, etc.) through a single standardized interface. The SMF and authentication server are designed to handle various authentication types without requiring separate transport network configurations, thus supporting diverse use cases while maintaining consistent and manageable transport requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If EAP-based secondary authentication is implemented, then authentication method flexibility is improved, but control plane processing load increases

Engineering Contradiction:
Improveauthentication method flexibilityVSAvoidcontrol plane processing capacity
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent extracts the computationally intensive authentication processing from the control plane SMF and delegates it to a separate authentication server. The SMF retains responsibility for authentication signaling and decision-making, while the authentication server handles the actual EAP method execution and credential verification. This extraction reduces the processing load on the control plane while maintaining authentication method flexibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11895229B2States secondary authentication of a user equipment
Publication Date: 2024.02.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11895229B2 patent drawing
  • US11895229B2 patent drawing
  • US11895229B2 patent drawing

AI summary

A network node operates a Session Management Function (SMF) in a control plane of a core network of a wireless network. The network node authenticates a User Equipment (UE) with an Extensible Authentication Protocol (EAP) server in a secondary authentication process that uses the SMF as an EAP authenticator. The EAP server is outside of the core network and the UE is separately authenticated with a further network node in the control plane of the core network via a primary authentication process. Authenticating the UE in the secondary authentication process comprises exchanging EAP messages between the SMF and the UE and between the SMF and the EAP server. The SMF authorizes a data session between the UE and the external network through a user plane of the core network based on the UE having successfully authenticated via both the primary authentication process and the secondary authentication process.