UE Access Authorization via EAP Attribute Embedding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP networks lack the ability to provide fine-grained authorization decisions for user equipment (UE) access to external networks, as they do not supply external AAA servers with relevant environmental attributes, leading to inadequate access control, especially in scenarios requiring location-based or time-dependent access restrictions, which forces enterprises to implement additional, costly security solutions.
Innovation Solution
Incorporating additional information, such as UE location and roaming status, into the EAP exchange during secondary authentication between the SMF and the external AAA server, allowing the external network to make informed authorization decisions based on Attribute-Based Access Control (ABAC) or Policy-Based Access Control (PBAC) policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If additional information (location, roaming status) is included in EAP exchange messages, then authorization decision precision is improved, but message complexity and processing overhead increase
Solution Approach 1:
The patent embeds additional authorization information (location, roaming status, time) directly within the existing EAP message structure. The SMF includes these attributes nested inside the EAP-AKA' or EAP-TLS authentication messages that are already being exchanged between the UE and external AAA server, rather than creating separate messaging protocols.
Solution Approach 2:
The patent modifies the EAP message parameters by adding new information elements (location coordinates, roaming status flags, time stamps) to the authentication exchange. This allows the external AAA server to perform attribute-based access control decisions using enriched message data without changing the fundamental EAP protocol structure.
2Reliability
If fine-grained access control is implemented using ABAC/PBAC policies, then security control capability is improved, but system complexity and implementation cost increase
Solution Approach 1:
The patent makes the existing external AAA server multi-functional by enabling it to perform both traditional credential-based authentication and attribute-based access control authorization. The same EAP exchange that verifies user credentials also transports authorization attributes, eliminating the need for separate authorization infrastructure.
Solution Approach 2:
The patent enables the external AAA server to autonomously perform fine-grained access control decisions using the authorization attributes received in the EAP messages. The server independently evaluates ABAC/PBAC policies based on the included information (location, time, roaming status) without requiring external policy decision points or additional hardware security modules.
3Measurement precision
If location-based and time-dependent access restrictions are enforced, then access control precision is improved, but information processing requirements and network overhead increase
Solution Approach 1:
The patent performs authorization information gathering during the authentication phase itself. The SMF collects location, time, and roaming status data before the actual access decision is made, and includes these attributes in the EAP exchange messages. This preliminary gathering eliminates the need for separate information collection steps later in the access control process.
Data Source
AI summary
Methods and means for providing a UE access to an external network are disclosed. In the methods it is determined that a that a secondary authentication procedure is required in order for the UE to access the external network, and then providing, to an entity of the external network, information relating to the UE. The UE related information is included in a message in relation to the secondary authentication procedure between the UE and the entity of the external network.


