SNPN Authentication Proxy for UEs Using External Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, a standalone non-public network (SNPN) cannot authenticate a device (UE) without a subscription, hindering access due to the lack of subscription and authentication mechanisms for UEs with external credentials.

Innovation Solution

The UE derives security keys using the Serving Network Name (SNN) or Service Provider Identifier (SP-ID) as access network identity parameters, and the Authentication Proxy (AUP) and AAA Server perform authorization and key derivation based on configured lists and preconfigured profiles, enabling authentication and key agreement with external credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a UE accesses an SNPN without a subscription, then the UE can access the network, but the SNPN cannot authenticate the UE using traditional subscription-based authentication mechanisms

Engineering Contradiction:
ImproveAccess capability for UEs without subscriptionVSAvoidAuthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an external AAA server as an intermediary authentication authority. The SNPN forwards authentication requests to this external AAA server, which validates UE credentials and issues authentication responses. This mediator enables UEs without direct SNPN subscriptions to be authenticated through third-party credential verification, resolving the contradiction between network access adaptability and authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication function is segmented into separate components: the SNPN handles network access control, while the external AAA server handles authentication. This segmentation allows the SNPN to access UEs without maintaining direct subscription records, while still ensuring reliable authentication through the specialized AAA server that validates credentials and manages security keys independently.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the SNPN uses traditional subscription-based authentication, then authentication is simple, but UEs without subscriptions cannot access the network

Engineering Contradiction:
ImproveSubscription flexibilityVSAvoidAuthentication mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The external AAA server acts as a mediator that simplifies the SNPN's operation. Instead of managing complex subscription records for every UE, the SNPN simply forwards authentication requests to the AAA server, which handles the complexity of credential validation and key management externally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The external AAA server provides universal authentication functionality that works for both subscribed and non-subscribed UEs. It handles multiple authentication scenarios (subscription-based and external credential-based) through a single unified mechanism, enabling the SNPN to maintain simple authentication logic while supporting flexible subscription models.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the SNPN sets up security according to 5G specifications, then security is ensured, but the authentication process becomes complex for UEs without subscriptions

Engineering Contradiction:
ImproveSecurity assuranceVSAvoidAuthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The external AAA server serves as a mediator that manages the complex security key derivation and 5G authentication procedures. The SNPN only needs to forward simple authentication requests to the AAA server, which handles the complex security setup including key derivation and validation, thus ensuring security while reducing the complexity burden on the SNPN and UE.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The AAA server performs preliminary security setup and key derivation before the actual authentication occurs. By pre-establishing security frameworks and validation mechanisms, the system ensures 5G-compliant security is in place before authentication begins, reducing the complexity of the authentication process itself while maintaining security assurance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260095446A1Authenticating a device not having a subscription in a network
Publication Date: 2026.04.02 LENOVO (SINGAPORE) PTE LTD
  • US20260095446A1 patent drawing
  • US20260095446A1 patent drawing
  • US20260095446A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for accessing a non-public network (NPN) using external credentials. One method of an authentication proxy includes receiving a registration request for a user equipment (UE), wherein the UE does not have a subscription with the mobile communication network; identifying a service provider of the UE; transmitting an authentication message to an authentication, authorization and accounting (AAA) server of the identified service provider; receiving an authentication response from the AAA server in response to successful authentication of the UE, the authentication response comprising a master session key (MSK); and deriving a set of security keys using the MSK.