Subnetwork Authentication via Local UE Trust and Mobility Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cellular networks face increased workload and complexity due to the requirement for core network servers to manage user equipment (UE) authentication processes in subnetworks, which can be alleviated by enabling UE-controlled authentication and subnetwork selection techniques.

Innovation Solution

UEs perform authentication using pre-shared cryptographic keys, base station assistance, or application layer services to establish trust within subnetworks, reducing the need for core network involvement and allowing flexible handover procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If core network servers manage UE authentication processes in subnetworks, then authentication security and control are improved, but network workload and complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into hierarchical levels: core network servers handle high-level authentication policies, while local subnetwork management nodes (SN-MN) handle actual UE authentication execution. This segmentation allows security to be maintained through distributed authentication decisions, reducing core network workload and overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A subnetwork management node (SN-MN) acts as an intermediary between UEs and core network servers. The SN-MN receives authentication requests from UEs, performs local authentication verification, and only communicates with core network servers when necessary. This intermediary approach maintains authentication security while significantly reducing network workload and complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If core network servers manage all authentication processes, then centralized control is improved, but network load increases

Engineering Contradiction:
Improvecentralized controlVSAvoidnetwork load
Core Design Contradiction:
Extent of automationVSLoss of energy

Solution Approach 1:

Authentication credentials and policies are pre-configured in subnetwork management nodes during network setup. When UEs join subnetworks, authentication is performed using these pre-configured credentials without requiring real-time core network server intervention. This preliminary action maintains centralized control through pre-established policies while dramatically reducing ongoing network load.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Subnetwork management nodes perform self-service authentication by verifying UE credentials locally using pre-configured authentication data. They autonomously make authentication decisions without continuously querying core network servers, enabling decentralized authentication execution that reduces network load while maintaining centralized policy control.

Inventive Principle:
Principle #25Self-service

3Speed

If UEs perform autonomous authentication using pre-shared keys, then authentication speed is improved, but security management complexity increases

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity management complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

Security credentials (pre-shared keys) are pre-distributed to UEs and subnetwork management nodes during device provisioning or initial network attachment. This preliminary credential distribution enables fast autonomous authentication without real-time key exchange, while the complexity of secure key management is handled during the initial setup phase rather than during authentication operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260074899A1Subnetwork Authentication and Mobility
Publication Date: 2026.03.12 APPLE INC
  • US20260074899A1 patent drawing
  • US20260074899A1 patent drawing
  • US20260074899A1 patent drawing

AI summary

Techniques are described herein for subnetwork selection. An example method can include processing, by a management node (MN) of a subnetwork, a connection establishment request for a user equipment (UE) to join the subnetwork. The process can further include processing, by the MN, cryptographic information based on the connection establishment request. The process can further include authenticating, by the MN, the UE based on the cryptographic information.