User Equipment Authentication Interface for Non-Public Network Key Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for user equipment in non-public networks face challenges in securely transferring an extended master session key from a non-public network authentication-authorization-accounting server to an authentication server function entity, particularly in scenarios involving wired internet-based connections, which poses security risks and compatibility issues with existing protocols.
Innovation Solution
The implementation of a user equipment that communicates with a non-public network authentication-authorization-accounting server to initiate a registration procedure and provide an authentication interface, enabling secure transfer of an extended master session key via a wired interface using pre-shared IDs, secret keys, or public key infrastructure, ensuring secure key derivation and authentication between the non-public network and the authentication server function entity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wired internet-based connections are used for key transfer between non-public network AAA server and authentication server function entity, then ease of operation and connectivity are improved, but security risks increase
Solution Approach 1:
The user equipment acts as an intermediary device that establishes a secure authentication interface between the non-public network AAA server and the authentication server function entity. The UE generates and manages security credentials (public/private key pairs, authentication keys) that mediate the secure communication channel, allowing wired connectivity while maintaining security through the UE's authentication mechanisms.
Solution Approach 2:
Security credentials and authentication interfaces are established in advance through a registration procedure before actual data transmission occurs. The UE performs preliminary authentication with the authentication server function entity, establishing security context and keys beforehand, so that subsequent wired connections inherit these pre-established security parameters rather than establishing them during data transfer.
2Adaptability or versatility
If multiple non-public network AAA servers connect to authentication server function entity, then adaptability and network capacity are improved, but device complexity and management difficulty increase
Solution Approach 1:
The user equipment is designed with universal authentication capabilities that allow it to serve multiple non-public network AAA servers simultaneously. The UE maintains a single authentication interface with the authentication server function entity that can authenticate multiple AAA servers through standardized protocols (RADIUS, DIAMETER), enabling one UE to manage multiple connections without proportionally increasing complexity.
Solution Approach 2:
The authentication interface uses homogeneous, standardized protocols (RADIUS, DIAMETER) for all connections between AAA servers and the authentication server function entity. This uniform approach allows multiple diverse AAA servers to connect through the same authentication mechanism, reducing management complexity compared to handling each server type individually.
3Reliability
If secure authentication interface is established through user equipment, then security is improved, but device complexity and authentication overhead increase
Solution Approach 1:
The user equipment performs self-service authentication by autonomously generating its own security credentials (public/private key pairs, authentication keys) and managing its own authentication interface with the authentication server function entity. The UE independently establishes security contexts without requiring manual configuration or external assistance, reducing operational complexity despite the enhanced security mechanisms.
Data Source
AI summary
A user equipment for a mobile telecommunications system, including circuitry configured to: communicate with a non-public network authentication-authorization-accounting server and initiate a registration procedure with the mobile telecommunications system; and provide an authentication interface between the non-public network authentication-authorization-accounting server and an authentication server function entity in the mobile tele-communications system.


