AAA Server Roaming Authentication Seamless Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Broadband Remote Access Server (BRAS) systems require users to re-authenticate when roaming between different access points or BRAS devices, disrupting network access convenience and smoothness.

Innovation Solution

An Authentication, Authorization, Accounting (AAA) server method and apparatus that detects roaming user terminals by sending authentication request packets with terminal information, notifies the new access interface to delete user entries, and sends authentication success packets to allow seamless access without re-authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the BRAS device requires re-authentication for roaming users, then security is improved, but user experience and access continuity deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-establishing user authentication state information in the BRAS device before roaming occurs. When a user roams to a new access point, the BRAS device already has the user's authentication state stored, allowing it to recognize the roaming user and maintain access without requiring re-authentication, thus resolving the contradiction between security and user experience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the BRAS device continuously monitors and updates user authentication state information. When a user roams, the system receives feedback about the user's new location and updates the authentication state accordingly, enabling seamless roaming while maintaining security through ongoing authentication verification

Inventive Principle:
Principle #23Feedback

2Speed

If the BRAS device stores user entry information locally, then access speed is improved, but adaptability to roaming deteriorates

Engineering Contradiction:
Improveaccess speedVSAvoidroaming adaptability
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The BRAS device is designed with multi-functionality to handle both local users and roaming users through a unified authentication mechanism. The device can store user entry information locally for fast access while simultaneously maintaining the capability to recognize and accommodate roaming users from different access points, achieving both speed and adaptability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts its behavior based on whether a user is local or roaming. The BRAS device dynamically updates user authentication state information when roaming occurs, allowing the system to maintain fast local access while adapting to roaming scenarios by updating stored information to reflect the user's current location and authentication state

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3855695B1Access authentication
Publication Date: 2024.01.17 NEW H3C TECH CO LTD
  • EP3855695B1 patent drawingFigure 1~2
  • EP3855695B1 patent drawingFigure 3~4
  • EP3855695B1 patent drawingFigure 5~6

AI summary

A method and an apparatus for authenticating an access are provided. When a first interface of a BRAS device does not find a user entry corresponding to a user terminal, the first interface sends an authentication request packet including terminal information of the user terminal to an AAA server. The AAA server notifies a second interface already accessed by the user terminal to delete a user entry corresponding to the user terminal when determining that the user terminal is an authenticated terminal and a roaming terminal, and sends an authentication success packet to the first interface when determining the deletion is completed, so that the first interface allows access of the user terminal and records the user entry corresponding to the user terminal in the first interface.