UE Access Authorization via EAP Attribute Embedding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP networks lack the ability to provide fine-grained authorization decisions for user equipment (UE) access to external networks, as they do not supply external AAA servers with relevant environmental attributes, leading to inadequate access control, especially in scenarios requiring location-based or time-dependent access restrictions, which forces enterprises to implement additional, costly security solutions.

Innovation Solution

Incorporating additional information, such as UE location and roaming status, into the EAP exchange during secondary authentication between the SMF and the external AAA server, allowing the external network to make informed authorization decisions based on Attribute-Based Access Control (ABAC) or Policy-Based Access Control (PBAC) policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If additional information (location, roaming status) is included in EAP exchange messages, then authorization decision precision is improved, but message complexity and processing overhead increase

Engineering Contradiction:
Improveauthorization decision precisionVSAvoidmessage complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent embeds additional authorization information (location, roaming status, time) directly within the existing EAP message structure. The SMF includes these attributes nested inside the EAP-AKA' or EAP-TLS authentication messages that are already being exchanged between the UE and external AAA server, rather than creating separate messaging protocols.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent modifies the EAP message parameters by adding new information elements (location coordinates, roaming status flags, time stamps) to the authentication exchange. This allows the external AAA server to perform attribute-based access control decisions using enriched message data without changing the fundamental EAP protocol structure.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If fine-grained access control is implemented using ABAC/PBAC policies, then security control capability is improved, but system complexity and implementation cost increase

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the existing external AAA server multi-functional by enabling it to perform both traditional credential-based authentication and attribute-based access control authorization. The same EAP exchange that verifies user credentials also transports authorization attributes, eliminating the need for separate authorization infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables the external AAA server to autonomously perform fine-grained access control decisions using the authorization attributes received in the EAP messages. The server independently evaluates ABAC/PBAC policies based on the included information (location, time, roaming status) without requiring external policy decision points or additional hardware security modules.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If location-based and time-dependent access restrictions are enforced, then access control precision is improved, but information processing requirements and network overhead increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidinformation processing requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent performs authorization information gathering during the authentication phase itself. The SMF collects location, time, and roaming status data before the actual access decision is made, and includes these attributes in the EAP exchange messages. This preliminary gathering eliminates the need for separate information collection steps later in the access control process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240187860A1Methods and means for providing access to external networks
Publication Date: 2024.06.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240187860A1 patent drawing
  • US20240187860A1 patent drawing
  • US20240187860A1 patent drawing

AI summary

Methods and means for providing a UE access to an external network are disclosed. In the methods it is determined that a that a secondary authentication procedure is required in order for the UE to access the external network, and then providing, to an entity of the external network, information relating to the UE. The UE related information is included in a message in relation to the secondary authentication procedure between the UE and the entity of the external network.