UE NAS Verification Code for Non-3GPP Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing authentication process in 3GPP networks, which relies on AAA servers for EAP-AKA protocol-based authentication, results in significant communication delays when user equipment (UE) accesses the network through non-3GPP networks.

Innovation Solution

The proposed method involves the UE generating a NAS verification code and an access request message, which includes an identifier and the verification code, sent to a Mobile Management Entity (MME) via an access point on a non-3GPP network, allowing for direct key derivation and authentication, thereby bypassing the need for AAA server authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAP-AKA protocol-based authentication is performed through AAA server when UE accesses 3GPP network via non-3GPP network, then network security authentication is ensured, but overall communication delay increases significantly

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcommunication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the authentication verification function from the AAA server and implements it directly in the MME. The MME obtains the NAS security context from the HSS and performs EPS-AKA authentication locally, eliminating the need for EAP-AKA protocol interactions with the AAA server. This extraction of the authentication function from the AAA server resolves the contradiction by maintaining authentication reliability while significantly reducing communication delay.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces the NAS security context as an intermediary mechanism that enables the MME to perform authentication independently. By obtaining the NAS security context (including authentication vector and key) from the HSS, the MME can act as its own authentication intermediary, bypassing the AAA server. This intermediary mechanism allows the system to maintain security authentication while eliminating the time-consuming EAP-AKA protocol steps.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If UE sends access request through non-3GPP network to 3GPP core network, then network convergence is achieved, but authentication process complexity increases

Engineering Contradiction:
Improvenetwork convergence capabilityVSAvoidauthentication process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the MME multi-functional by enabling it to perform both mobility management and authentication functions. The MME obtains the NAS security context from the HSS and performs EPS-AKA authentication locally, combining multiple functions in a single network element. This universality simplifies the authentication process by eliminating the need for separate AAA server interactions while maintaining network convergence capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements preliminary action by having the MME obtain the NAS security context and perform authentication verification before the UE completes the access process. The MME retrieves the authentication vector and key from the HSS in advance, and performs the authentication check before allowing the UE to access the 3GPP core network services. This preliminary authentication action simplifies the overall process by preventing failed authentication attempts later.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3657835B1Access method of user equipment, user equipment and computer-readable storage medium
Publication Date: 2023.09.20 HUAWEI TECH CO LTD
  • EP3657835B1 patent drawingFigure 1
  • EP3657835B1 patent drawingFigure 2
  • EP3657835B1 patent drawingFigure 3

AI summary

The present invention provides an access method of UE and a UE, and relates to the wireless communications field. The method includes: sending, by a UE to a first network device on a 3GPP network by using a second network device on a non-3GPP network, an access request message including a NAS verification code generated by the UE according to a security context stored in the UE.The security context is shared between the UE and the first network device after the UE is successfully authenticated on the 3GPP network.