Dynamic AAA Server Routing via Inner User Policy Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless Internet environments lack flexibility in routing user authentication information to the appropriate AAA server, relying on static routes based on outer identities, which can be inadequate for directing inner user authentication requests to specific servers.

Innovation Solution

Implementing a policy engine to evaluate inner user information against predefined conditions, allowing for dynamic routing of user authentication requests to the appropriate AAA server using a tunneled Extensible Authentication Protocol (EAP), enabling flexible routing based on inner user evaluation and AAA attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static routes based on outer identities are used for routing authentication requests, then the routing configuration is simple, but the flexibility to direct inner user authentication requests to specific AAA servers is insufficient

Engineering Contradiction:
Improverouting flexibilityVSAvoidrouting configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic routing by introducing a policy engine that evaluates inner user information and dynamically determines the appropriate AAA server for routing authentication requests. This replaces static route configurations with adaptive routing decisions based on real-time user attributes and policy conditions, allowing the system to flexibly direct authentication requests to specific AAA servers without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a policy engine as an intermediary component between the authentication system and AAA servers. This policy engine evaluates inner user information against defined policies and determines the appropriate routing destination, acting as a mediator that translates authentication requests into dynamically selected AAA server routes based on user-specific conditions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a policy engine is implemented to evaluate inner user information, then routing flexibility is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication routing flexibilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The policy engine is designed as a universal component that handles multiple authentication routing scenarios through a single unified evaluation mechanism. It can assess various inner user information types (usernames, attributes, conditions) and route to different AAA servers using the same policy evaluation framework, reducing the need for separate routing logic for each authentication scenario and thereby managing complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity by changing parameters dynamically rather than altering system architecture. The policy engine evaluates user-specific parameters (inner user information, attributes, conditions) and adjusts routing decisions based on these parameter changes, allowing flexible authentication routing without requiring complex structural modifications to the underlying system.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8776181B1Methods for authenticating and authorizing a mobile device using tunneled extensible authentication protocol
Publication Date: 2014.07.08 AMDOCS DEV LTD
  • US8776181B1 patent drawing
  • US8776181B1 patent drawing
  • US8776181B1 patent drawing

AI summary

Methods for authenticating and authorizing a mobile device using tunneled extensible authentication protocol are provided. The methods include evaluating an inner user identifier against a policy engine to determine a home AAA server to route an access request for inner user authentication. Instead of having a static route configured based on an outer identifier/roaming identity, the policy engine can have multiple rules and actions for routing the request. The evaluation can be based on the conditions of the inner user identifier and or other AAA attributes received in the request. The request is transmitted within a secure communication tunnel. There are several embodiments of evaluating an inner user identifier against a policy engine.