Intra-realm AAA Fallback via Sub-Realm Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current AAA infrastructure in single-realm systems faces challenges in handling server failures, particularly in large networks, as existing fallback mechanisms fail to ensure reliable and instant delegation of clients to backup servers and efficient traffic handling.

Innovation Solution

The solution involves splitting the large realm into sub-realms and deploying back-2-back AAA agents that act as relay, proxy, or redirect agents, enabling sub-realm based routing to facilitate instant and reliable client delegation to backup servers, while maintaining transparency for the existing AAA infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single-realm AAA infrastructure is used, then the system is simple to manage, but server failures cannot be handled reliably in large networks

Engineering Contradiction:
Improveserver failure handlingVSAvoidrealm structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the single realm into multiple sub-realms, each with its own AAA servers. This segmentation allows failure isolation within sub-realms while maintaining overall system reliability. The single-realm structure is preserved at the top level, but functional segmentation is introduced through sub-realms with independent failure domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces backup AAA servers as intermediary components that stand by in alternative sub-realms. These backup servers act as mediators that take over client connections when primary servers fail, enabling reliable failure handling without requiring complex real-time coordination across the entire single-realm infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If known fallback mechanisms are used in single-realm AAA systems, then some failure detection is possible, but client delegation to backup servers is not reliable or instant

Engineering Contradiction:
Improveclient delegation to backup serverVSAvoidfailure detection and switchover time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-configures backup AAA servers in alternative sub-realms before any failure occurs. Clients are pre-associated with multiple sub-realms, and backup servers are pre-positioned and ready. When a failure is detected, the switchover can proceed instantly without time-consuming configuration changes, as all necessary routing and association information is already in place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic failure detection and automatic client redirection to backup servers. The system continuously monitors server status and dynamically adjusts client connections in real-time. When a primary server fails, the system automatically detects the failure and redirects clients to available backup servers without manual intervention, achieving both reliability and speed.

Inventive Principle:
Principle #15Dynamics

3Area of stationary object

If regional sites are deployed across large distances, then coverage is improved, but failure impact and routing complexity increase

Engineering Contradiction:
Improvenetwork coverage areaVSAvoidrouting configuration
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent segments the large geographic network into multiple sub-realms, each serving specific regional areas. This segmentation confines failure impact to local sub-realms rather than propagating across the entire network. Routing configurations are simplified within each sub-realm, and the modular structure makes it easier to manage and scale the network across large distances.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by making each sub-realm autonomous with its own AAA servers and failure handling capabilities. Each regional site has localized backup mechanisms that operate independently, tailored to their specific geographic and operational requirements. This allows optimized failure detection and recovery within each local area without requiring complex centralized coordination.

Inventive Principle:
Principle #3Local quality

4Reliability

If existing AAA infrastructure is modified to support sub-realms, then failure handling improves, but infrastructure complexity increases

Engineering Contradiction:
Improveserver failure fallbackVSAvoidAAA infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes existing AAA servers and infrastructure components multi-functional by enabling them to serve dual roles: primary servers handle normal operations, while the same infrastructure components function as backup servers when needed. The sub-realm structure allows existing servers to be configured for both primary and backup functions, reducing the need for separate dedicated backup infrastructure and minimizing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates copies of AAA server functionality within different sub-realms rather than requiring entirely separate backup infrastructure. Each sub-realm has replicated server capabilities that can take over during failures. This copying approach maintains infrastructure simplicity by using the same server types and configurations across sub-realms, rather than requiring specialized backup hardware or complex additional components.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2422502B1Intra-realm AAA fallback mechanism
Publication Date: 2016.10.05 NOKIA SOLUTIONS & NETWORKS OY
  • EP2422502B1 patent drawingFigure 1
  • EP2422502B1 patent drawingFigure 2
  • EP2422502B1 patent drawingFigure 3

AI summary

There is provided an intra-realm AAA (authentication, authorization and accounting) fallback mechanism, wherein the single global realm may be divided in one or more sub-realms. The thus presented mechanism exemplarily comprises detecting a failure of an authentication server serving at least one authentication client within a first sub-realm of a single-realm authentication system, and routing authentication messages of the at least one authentication client to a fallback authentication server within a second sub-realm of the single-realm authentication system, wherein routing may exemplarily comprise sub-realm based source routing.