IP Library Patent Application 17299128
Patent Application
App. No. 17/299,128

SECONDARY AUTHENTICATION FOR WWAN VPN

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/299,128
Abstract

Systems and methods of providing secondary authentication credentials for an external network are described. The credentials are provided from the UE to the GGSN via the SGSN during establishment of a PDN connection for the UE in a NAS message. The SGSN receives an Activate PDP Context Request from the UE and sends to the GGSN a Create PDP Context Request. The Requests include a PCO IE with the credentials. The GGSN determines a RADIUS and/or DHCP server to be used for IP address allocation, a protocol to be used with the server, and security features to use to dialogue with the server. The GGSN obtains the IP address from the server and provides the IP address to the UE via the SGSN via Create PDP Context Response.

Claims (48)

1 . An apparatus of a packet gateway (P-GW), the apparatus comprising:

processing circuitry configured to:

decode, from a Serving General Packet Radio Service (GPRS) Support Node (SGSN), secondary authentication credentials of a user equipment (UE) for trusted access during establishment of a packet data network (PDN) connection for the UE; and

authenticate the UE with at least one external server using the secondary authentication credentials; and

a memory configured to store the secondary authentication credentials.

2 . The apparatus of claim 1 , wherein the PCO IE is contained in a non-access stratum (NAS) message carried by a packet data network (PDN) Connectivity Request.

3 . The apparatus of claim 2 , wherein the processing circuitry is further configured to decode, from the SGSN, a Create PDP Context Request that comprises the secondary authentication credentials.

4 . The apparatus of claim 1 , wherein the secondary authentication credentials are provided in a Protocol Configuration Option (PCO) information element (IE).

5 . The apparatus of claim 4 , wherein the PCO IE comprises at least one of a Password Authentication Protocol (PAP) or Challenge Handshake Authentication Protocol (CHAP) user credentials.

6 . The apparatus of claim 1 , wherein the processing circuitry is further configured to decode, from the UE via an S2c interface, the secondary authentication credentials based on Internet Engineering Task Force (IETF) Request for Comments (RFC) 4739 during establishment of security association signaling via Internet Key Exchange Version 2 (IKEv2).

7 . The apparatus of claim 1 , wherein the processing circuitry is further configured to decode, from the UE via an S2b interface, the secondary authentication credentials based on Internet Engineering Task Force (IETF) Request for Comments (RFC) 4739 during establishment of security association signaling via Internet Key Exchange Version 2 (IKEv2), and the secondary authentication credentials are provided in an Additional Protocol Configuration Options (APCO) information element (IE) if multiple authentications are supported.

8 . The apparatus of claim 7 , wherein:

the APCO IE includes a virtual private network (VPN) context that comprises at least one of: VPN server/gateway Endpoint Address, VPN tunneling type, or VPN security credential/certificate.

9 . The apparatus of claim 1 , wherein the processing circuitry is further configured to:

encode, for transmission to a Remote Authentication Dial In User Service (RADIUS) server, a RADIUS Access-Request message comprising the secondary authentication credentials; and

decode, from the RADIUS server in response to transmission of the RADIUS Access-Request message, a RADIUS Access-Accept message comprising the secondary authentication credentials.

10 . The apparatus of claim 9 , wherein:

the processing circuitry is further configured to allocate a RADIUS client without allocation of a DHCP client,

the RADIUS Access-Request further includes a configuration that comprises the RADIUS client, and

the RADIUS Access-Request further includes another configuration that comprises the RADIUS client and the RADIUS server.

11 . The apparatus of claim 9 , wherein the processing circuitry is further configured to:

allocate a RADIUS client and a DHCP client,

encode a DHCP Discover message, the DHCP Discover message comprising a configuration that includes the DCHP client, and

decode the DHCP Offer message from the DHCP server, the DHCP Offer method comprising another configuration that comprises the DCHP client.

12 . An apparatus of a Serving General Packet Radio Service (GPRS) Support Node (SGSN), the apparatus comprising:

processing circuitry configured to:

decode, from a user equipment (UE), secondary authentication credentials for trusted access during establishment of a packet data network (PDN) connection; and

encode, for transmission to a PDN gateway (P-GW), the secondary authentication credentials for authentication of the UE with at least one external server using the secondary authentication credentials,

wherein the secondary authentication credentials are provided in a Protocol Configuration Option (PCO) information element (IE);

a memory configured to store the secondary authentication credentials.

13 . The apparatus of claim 12 , wherein the PCO IE is contained in a non-access stratum (NAS) message carried by a packet data network (PDN) Connectivity Request.

14 . The apparatus of claim 13 , wherein the processing circuitry is further configured to decode, from the UE, an Activate PDP Context Request that comprises the secondary authentication credentials and encode, for transmission to the P-GW, a Create PDP Context Request that comprises the secondary authentication credentials.

15 . The apparatus of claim 12 , wherein the PCO IE comprises at least one of a Password Authentication Protocol (PAP) or Challenge Handshake Authentication Protocol (CHAP) user credentials.

16 . A non-transitory computer-readable storage medium that stores instructions for execution by one or more processors of a Gateway GPRS Support Node (GGSN), the one or more processors to configure the GGSN to, when the instructions are executed:

receive, from a Serving General Packet Radio Service (GPRS) Support Node (SGSN), a Create PDP Context Request comprising a Protocol Configuration Option (PCO) information element (IE);

determine, from the PCO IE, secondary authentication credentials of a user equipment (UE) for external authentication of the UE, a server to be used for internet protocol (IP) address allocation, and a protocol to be used with the server;

communicate with the server to obtain an IP address; and

send to the UE via the SGSN, the IP address.

17 . The medium of claim 16 , wherein the PCO IE comprises at least one of a Password Authentication Protocol (PAP) or Challenge Handshake Authentication Protocol (CHAP) user credentials.

18 . The medium of claim 16 , wherein the one or more processors further configure the GGSN to, when the instructions are executed:

receive, from the UE via an S2c interface, the secondary authentication credentials based on Internet Engineering Task Force (IETF) Request for Comments (RFC) 4739 during establishment of security association signaling via Internet Key Exchange Version 2 (IKEv2).

19 . The medium of claim 16 , wherein the one or more processors further configure the GGSN to, when the instructions are executed:

receive, from the UE via an S2b interface, the secondary authentication credentials based on Internet Engineering Task Force (IETF) Request for Comments (RFC) 4739 during establishment of security association signaling via Internet Key Exchange Version 2 (IKEv2), and the secondary authentication credentials are provided in an Additional Protocol Configuration Options (APCO) information element (IE) if multiple authentications are supported.

20 . The medium of claim 19 , wherein:

the APCO IE includes a virtual private network (VPN) context that comprises at least one of: VPN server/gateway Endpoint Address, VPN tunneling type, or VPN security credential/certificate.

21 . The medium of claim 16 , wherein the one or more processors further configure the GGSN to, when the instructions are executed:

send to a Remote Authentication Dial In User Service (RADIUS) server, a RADIUS Access-Request message comprising the secondary authentication credentials; and

receive, from the RADIUS server in response to transmission of the RADIUS Access-Request message, a RADIUS Access-Accept message comprising the secondary authentication credentials.