WLAN Authentication Reuse for 5G Core Network Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 3GPP standards require User Equipment (UE) to re-authenticate with the 5G core network when registering after connecting to a WLAN Access Network using 5G credentials without prior 5G core network registration, despite prior authentication, leading to inefficiency in signaling and processing.

Innovation Solution

Optimize UE registration with the 5G core network by skipping redundant authentication if both UE and 5G core network have successfully conducted a Non-Seamless WLAN Offload (NSWO) authentication procedure, utilizing security keys generated during the prior authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UE re-authenticates with 5G core network when registering after WLAN connection, then security is maintained, but signaling load and processing requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling load
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent performs authentication in advance during the WLAN connection establishment, so that when registration is needed later, the authentication results can be reused. The AUSF performs EAP authentication with the UE during WLAN setup, generating authentication credentials that are stored and later used to bypass full authentication during registration, thus reducing subsequent signaling load while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent makes the authentication credentials generated during WLAN authentication universally applicable for both WLAN access and 5G core network registration. The same EAP authentication credentials serve dual purposes: establishing WLAN connectivity and enabling future 5G registration without re-authentication, thereby reducing redundant signaling while maintaining security across different network functions

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If UE re-authenticates with 5G core network when registering after WLAN connection, then authentication security is ensured, but processing time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication in advance during the WLAN connection establishment phase, generating authentication credentials before they are needed for registration. This preliminary authentication stored in the UE and AUSF allows subsequent registration to proceed without repeating the full authentication process, thus reducing processing time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the UE to skip the full authentication process during registration by using previously obtained authentication credentials. When the UE needs to register with the 5G core network after WLAN connection, it can directly use the stored EAP credentials to bypass time-consuming authentication steps, rushing through the registration process efficiently while security is maintained through validation of the pre-established credentials

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS20250254639A1Registering with a mobile network after a first authentication with a WLAN access network
Publication Date: 2025.08.07 LENOVO (SINGAPORE) PTE LTD
  • US20250254639A1 patent drawing
  • US20250254639A1 patent drawing
  • US20250254639A1 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for registering with a core network after NSWO authentication. One apparatus includes a processor coupled to a transceiver, the processor configured to cause the apparatus to connect to a WLAN AN using credentials associated with a network, including performing a first authentication procedure without registering the apparatus with the network. The processor determines to register with the network and the transceiver sends a first message including a first container derived based on information generated during the first authentication procedure, where the first message initiates registration with the network. The transceiver receives a second message including a second container derived based on information generated during the first authentication procedure. The processor registers with the network based on validating the second container.