UE Access Mode Selection for Trusted WLAN Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for authentication in 3GPP networks require modifications to the TWAN-AAA Server interface and extensive configuration of SSID-related information, complicating trusted WLAN access without impacting user equipment, especially in scenarios with numerous SSIDs and varying network agreements.
Innovation Solution
The user equipment (UE) selects an access type by indicating a service set identifier (SSID), allowing the TWAN to advertise and compare requested access modes with its capabilities, and the AAA server determines permitted access modes, eliminating the need to send SSIDs to the AAA server and simplifying the TWAN-AAA Server interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the TWAN forwards the SSID to the 3GPP AAA server for access authentication, then the AAA server can make decisions about service and system access, but modifications to the TWAN-AAA Server interface are required
Solution Approach 1:
The invention extracts the SSID forwarding function from the TWAN-AAA Server interface interaction. Instead of the TWAN forwarding the SSID to the AAA server, the UE itself includes the selected SSID in the authentication request message sent directly to the AAA server. This removes the need for interface modifications while preserving authentication reliability.
Solution Approach 2:
The UE acts as an intermediary that selects and forwards the appropriate SSID to the AAA server during authentication. This mediates between the TWAN's capability advertisement and the AAA server's authentication decision, eliminating the need for direct SSID forwarding from TWAN to AAA server.
2Adaptability or versatility
If the 3GPP AAA server is configured with all relevant SSID information, then it can authenticate subscribers across multiple WLAN operators, but the configuration becomes extensive and complex
Solution Approach 1:
The UE performs self-service by autonomously selecting the appropriate SSID from the advertised list based on its own criteria (user preferences, service requirements, etc.). This eliminates the need for the AAA server to be pre-configured with extensive SSID information, as the UE brings the necessary selection logic to the authentication process itself.
Solution Approach 2:
Instead of the AAA server being configured with all SSID information and making selection decisions, the inversion places the SSID selection capability at the UE side. The UE receives the advertised SSID list and independently determines which SSID to use, reversing the traditional centralized configuration approach.
3Adaptability or versatility
If the TWAN advertises multiple access authentication modes, then the UE can select the most suitable mode, but the UE must be impacted with additional selection logic
Solution Approach 1:
The TWAN acts as an intermediary that simplifies the process for the UE. Instead of requiring complex UE logic to evaluate and select among multiple access modes, the TWAN advertises the available modes and their characteristics, and the UE can make simple selections based on user preferences or basic criteria without implementing complex selection algorithms.
Solution Approach 2:
The TWAN provides a simplified copy or representation of the available access modes through advertisement messages, containing essential information needed for UE selection without requiring the UE to maintain complex internal models of all possible access modes and their characteristics.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Access mode selection based on user equipment selected access network identity may be useful, for example, with respect to the authentication in third generation partnership project (3GPP) networks of subscribers attaching to a trusted wireless local area network (WLAN) access network (TWAN). A method of access mode selection can include informing, in a request, an authentication server regarding at least one access mode for a user equipment. The method can also include selecting a mode of the at least one access mode to use with respect to the user equipment based on a response received from the authentication server in response to the request.