Trusted WLAN Access Gateway Bridging Authentication Protocols

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for user equipment (UE) accessing a WLAN cannot seamlessly transition to access a mobile network, as they rely on username and password authentication, which is not compatible with mobile network access protocols.

Innovation Solution

A method and system that obtain a user identity for UE to access a mobile network by associating the WLAN user identity with a mobile network identity, using a Trusted WLAN Access Gateway (TWAG) and AAA servers to enable access, utilizing user identities such as MSISDN and IMSI, and authentication methods like Portal or PEAP.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If username and password authentication is used for WLAN access, then the authentication process is simple and easy to implement, but the UE cannot access the mobile network

Engineering Contradiction:
Improveauthentication processVSAvoidmobile network access capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a Trusted WLAN Access Gateway (TWAG) as an intermediary component that bridges WLAN authentication and mobile network access. The TWAG receives the username and password from the UE, obtains the corresponding mobile network user identity (IMSI/MSISDN) from the HSS/HLR, and facilitates both WLAN access and mobile network access, thus resolving the contradiction between simple authentication and mobile network compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The TWAG is designed with multi-functionality to serve multiple purposes: it performs WLAN authentication, obtains mobile network user identities, establishes PDP contexts for mobile network access, and manages both WLAN and mobile network sessions. This universal approach allows a single system to handle both authentication methods simultaneously

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a separate mobile communication network infrastructure is used for authentication, then mobile network access is enabled, but the system complexity increases

Engineering Contradiction:
Improvemobile network access capabilityVSAvoidauthentication system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the WLAN access control function and mobile network access function into a single TWAG component. Instead of using separate authentication infrastructures, the TWAG integrates WLAN authentication (using username/password) with mobile network authentication (using IMSI/MSISDN), obtaining user identities from the HSS/HLR and establishing both types of access through one unified system

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a correspondence relationship between WLAN user identities (username/password) and mobile network user identities (IMSI/MSISDN) by obtaining the mobile identity information from the HSS/HLR based on the WLAN authentication credentials. This copying of identity information allows seamless transition between authentication systems

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2858395B1Method and system for accessing mobile network
Publication Date: 2020.06.24 HUAWEI TECH CO LTD
  • EP2858395B1 patent drawingFigure 1~2
  • EP2858395B1 patent drawingFigure 3
  • EP2858395B1 patent drawingFigure 4

AI summary

The present invention relates to a method, an apparatus, and a system for accessing a mobile network. The method for accessing a mobile network includes: obtaining a user identity for a user equipment UE to access a wireless local area network WLAN; obtaining, according to the user identity for the UE to access the WLAN, a user identity that is for the UE to access a mobile network and is associated with the user identity for the UE to access the WLAN; and sending the user identity for the UE to access the mobile network to a trusted wireless access gateway TWAG, so as to instruct the TWAG to enable the UE to access the mobile network. Through association between a WLAN identity and a mobile user identity, a user identity for a UE to access a mobile network can be authenticated, thereby implementing access of the UE to the mobile network.