SNPN Authentication Proxy for UEs Using External Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication systems, a standalone non-public network (SNPN) cannot authenticate a device (UE) without a subscription, hindering access due to the lack of subscription and authentication mechanisms for UEs with external credentials.
Innovation Solution
The UE derives security keys using the Serving Network Name (SNN) or Service Provider Identifier (SP-ID) as access network identity parameters, and the Authentication Proxy (AUP) and AAA Server perform authorization and key derivation based on configured lists and preconfigured profiles, enabling authentication and key agreement with external credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a UE accesses an SNPN without a subscription, then the UE can access the network, but the SNPN cannot authenticate the UE using traditional subscription-based authentication mechanisms
Solution Approach 1:
The patent introduces an external AAA server as an intermediary authentication authority. The SNPN forwards authentication requests to this external AAA server, which validates UE credentials and issues authentication responses. This mediator enables UEs without direct SNPN subscriptions to be authenticated through third-party credential verification, resolving the contradiction between network access adaptability and authentication reliability.
Solution Approach 2:
The authentication function is segmented into separate components: the SNPN handles network access control, while the external AAA server handles authentication. This segmentation allows the SNPN to access UEs without maintaining direct subscription records, while still ensuring reliable authentication through the specialized AAA server that validates credentials and manages security keys independently.
2Adaptability or versatility
If the SNPN uses traditional subscription-based authentication, then authentication is simple, but UEs without subscriptions cannot access the network
Solution Approach 1:
The external AAA server acts as a mediator that simplifies the SNPN's operation. Instead of managing complex subscription records for every UE, the SNPN simply forwards authentication requests to the AAA server, which handles the complexity of credential validation and key management externally.
Solution Approach 2:
The external AAA server provides universal authentication functionality that works for both subscribed and non-subscribed UEs. It handles multiple authentication scenarios (subscription-based and external credential-based) through a single unified mechanism, enabling the SNPN to maintain simple authentication logic while supporting flexible subscription models.
3Reliability
If the SNPN sets up security according to 5G specifications, then security is ensured, but the authentication process becomes complex for UEs without subscriptions
Solution Approach 1:
The external AAA server serves as a mediator that manages the complex security key derivation and 5G authentication procedures. The SNPN only needs to forward simple authentication requests to the AAA server, which handles the complex security setup including key derivation and validation, thus ensuring security while reducing the complexity burden on the SNPN and UE.
Solution Approach 2:
The AAA server performs preliminary security setup and key derivation before the actual authentication occurs. By pre-establishing security frameworks and validation mechanisms, the system ensures 5G-compliant security is in place before authentication begins, reducing the complexity of the authentication process itself while maintaining security assurance.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for accessing a non-public network (NPN) using external credentials. One method of an authentication proxy includes receiving a registration request for a user equipment (UE), wherein the UE does not have a subscription with the mobile communication network; identifying a service provider of the UE; transmitting an authentication message to an authentication, authorization and accounting (AAA) server of the identified service provider; receiving an authentication response from the AAA server in response to successful authentication of the UE, the authentication response comprising a master session key (MSK); and deriving a set of security keys using the MSK.


