ZTNA Controller Merging 3GPP Credentials for Enterprise Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Zero-Trust Network Access (ZTNA) systems require two independent authentication procedures, consuming network resources and causing delays due to the invisibility of connectivity-layer identity information to the application layer, necessitating improved authentication methods for enterprise network access.

Innovation Solution

A method and system where a Zero-Trust Network Access (ZTNA) controller and User Data Management (UDM) entity collaborate to authenticate subscribers using 3GPP credentials, allowing access to an enterprise network only when policy allows, leveraging a single set of identifiers for both connectivity and application layer authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two independent authentication procedures are performed for connectivity layer and application layer, then authentication security is improved, but network resource consumption increases and processing time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the connectivity layer authentication and application layer authentication into a single unified authentication procedure. The ZTNA controller utilizes the 3GPP credentials obtained during connectivity authentication to directly authenticate the subscriber at the application layer, eliminating the need for separate authentication procedures and thereby reducing network resource consumption while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the 3GPP credentials serve multiple functions: they are used both for connectivity layer authentication and for application layer authentication. This multi-functionality allows a single set of credentials to fulfill multiple authentication requirements, reducing the overhead of managing separate authentication mechanisms

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If two independent authentication procedures are performed, then authentication security is improved, but processing time increases causing delay

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines two sequential authentication procedures into one integrated process. By using the ZTNA controller to leverage 3GPP credentials for both connectivity and application layer authentication, the system eliminates the time delay associated with performing separate authentication steps, thereby reducing access delay while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs the application layer authentication preparation during the connectivity layer authentication process. The ZTNA controller pre-establishes the authentication context using 3GPP credentials, so that when the subscriber requests access, the authentication can be completed more quickly without requiring a separate full authentication procedure

Inventive Principle:
Principle #10Preliminary action

3Productivity

If connectivity layer identity information is made visible to application layer, then authentication efficiency is improved, but network complexity increases

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidnetwork complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces the ZTNA controller as an intermediary component that bridges the connectivity layer and application layer. This mediator obtains 3GPP credentials from the connectivity layer authentication and uses them for application layer authentication, enabling efficient authentication without requiring direct visibility of connectivity layer identity information throughout the network

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240196211A1Authentication of Subscriber Entities to Enterprise Networks
Publication Date: 2024.06.13 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240196211A1 patent drawing
  • US20240196211A1 patent drawing
  • US20240196211A1 patent drawing

AI summary

There is provided mechanisms for controlling access of a subscriber entity to an application service of an enterprise network. A method is performed by a ZTNA controller. The method comprises obtaining an indication that the subscriber entity requests to access the application service of the enterprise network. The indication is obtained via an access network to which the subscriber entity is operatively connected. The method comprises providing a request for user information of the subscriber entity to a UDM entity provided in a core network to which the access network is operatively connected. The request for user information comprises an identifier of the subscriber entity. The method comprises obtaining the user information of the subscriber entity from the UDM entity. The user information indicates successful 3GPP credentials based authentication of the subscriber entity performed by the UDM entity. The method comprises granting access for the subscriber entity to the application service of the enterprise network only when a policy associated to the user information allows so.