UE Relay Authentication Reducing Terminal Complexity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current ProSe technology faces complexity and cost issues due to the need for multiple authentication protocols, leading to inefficiencies and poor user experience in authenticating user equipment (UE) accessing a network through a UE-R, especially when unauthorized access poses a security threat.
Innovation Solution
Implementing EPS AKA authentication within the UE-R system, allowing UE to send identification information for authentication vector acquisition, simplifying the authentication process and reducing terminal complexity and costs by eliminating the need for additional protocols like EAP-AKA.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP-AKA authentication protocol is used to authenticate UE accessing network via UE-R, then network security is improved, but terminal complexity and costs increase
Solution Approach 1:
The patent extracts the authentication protocol requirement from the terminal by implementing authentication functionality in the network side (MME and HSS). The UE only needs to support basic EPS AKA authentication, while the complex EAP-AKA authentication is performed by the network infrastructure, thereby reducing terminal complexity while maintaining security.
Solution Approach 2:
The patent introduces the MME as an intermediary between the UE and HSS for authentication. The MME acts as a mediator that receives authentication requests from UE-R, obtains authentication vectors from HSS, and completes the authentication process, thereby simplifying the terminal's authentication burden while ensuring security through the established EPS AKA protocol.
2Reliability
If EAP-AKA authentication protocol is used to authenticate UE, then authentication security is improved, but authentication efficiency deteriorates
Solution Approach 1:
The patent implements preliminary action by pre-obtaining authentication vectors (including RAND, AUTN, XRES, and Kasme) from the HSS before the actual authentication takes place. This allows the authentication process to proceed more efficiently with pre-computed values, reducing the time required during the actual authentication while maintaining security through the use of these pre-prepared authentication elements.
3Adaptability or versatility
If UE supports both EPS AKA and EAP-AKA authentication, then authentication compatibility is improved, but terminal costs increase
Solution Approach 1:
The patent applies universality by making the network infrastructure (MME and HSS) capable of handling authentication for both direct network access and UE-R relay access scenarios. The network side is designed to be multi-functional, supporting different authentication modes without requiring the terminal to support multiple authentication protocols, thereby achieving authentication compatibility while keeping terminal costs low.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention disclose a terminal authenticating method, including: receiving, by a UE-to-network relay UE-R, a first request message sent by user equipment UE; sending, by the UE-R, a second request message to a control network element according to the first request message sent by the UE; receiving, by the UE-R, an authentication request message sent by the control network element, and determining whether the authentication request message is for authenticating on the UE; if the authentication request message is for authenticating on the UE, sending, by the UE-R, an authentication request message to the UE; and receiving, by the UE-R, an authentication response message sent by the UE according to the authentication request message, and sending the authentication response message to the control network element. The embodiments of the present invention further disclose a terminal authentication apparatus. The present invention has the following advantages: Operations are simple, complexity and costs of a terminal can be reduced, and efficiency in authenticating a terminal and user experience are improved.