Trusted WLAN Access Gateway Bridging Authentication Protocols
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for user equipment (UE) accessing a WLAN cannot seamlessly transition to access a mobile network, as they rely on username and password authentication, which is not compatible with mobile network access protocols.
Innovation Solution
A method and system that obtain a user identity for UE to access a mobile network by associating the WLAN user identity with a mobile network identity, using a Trusted WLAN Access Gateway (TWAG) and AAA servers to enable access, utilizing user identities such as MSISDN and IMSI, and authentication methods like Portal or PEAP.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If username and password authentication is used for WLAN access, then the authentication process is simple and easy to implement, but the UE cannot access the mobile network
Solution Approach 1:
The patent introduces a Trusted WLAN Access Gateway (TWAG) as an intermediary component that bridges WLAN authentication and mobile network access. The TWAG receives the username and password from the UE, obtains the corresponding mobile network user identity (IMSI/MSISDN) from the HSS/HLR, and facilitates both WLAN access and mobile network access, thus resolving the contradiction between simple authentication and mobile network compatibility
Solution Approach 2:
The TWAG is designed with multi-functionality to serve multiple purposes: it performs WLAN authentication, obtains mobile network user identities, establishes PDP contexts for mobile network access, and manages both WLAN and mobile network sessions. This universal approach allows a single system to handle both authentication methods simultaneously
2Adaptability or versatility
If a separate mobile communication network infrastructure is used for authentication, then mobile network access is enabled, but the system complexity increases
Solution Approach 1:
The patent merges the WLAN access control function and mobile network access function into a single TWAG component. Instead of using separate authentication infrastructures, the TWAG integrates WLAN authentication (using username/password) with mobile network authentication (using IMSI/MSISDN), obtaining user identities from the HSS/HLR and establishing both types of access through one unified system
Solution Approach 2:
The system creates a correspondence relationship between WLAN user identities (username/password) and mobile network user identities (IMSI/MSISDN) by obtaining the mobile identity information from the HSS/HLR based on the WLAN authentication credentials. This copying of identity information allows seamless transition between authentication systems
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention relates to a method, an apparatus, and a system for accessing a mobile network. The method for accessing a mobile network includes: obtaining a user identity for a user equipment UE to access a wireless local area network WLAN; obtaining, according to the user identity for the UE to access the WLAN, a user identity that is for the UE to access a mobile network and is associated with the user identity for the UE to access the WLAN; and sending the user identity for the UE to access the mobile network to a trusted wireless access gateway TWAG, so as to instruct the TWAG to enable the UE to access the mobile network. Through association between a WLAN identity and a mobile user identity, a user identity for a UE to access a mobile network can be authenticated, thereby implementing access of the UE to the mobile network.