Network AAA System with Service Accounting Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network authentication, authorization, and accounting (AAA) systems face challenges in providing Quality of Service (QoS) assurance and efficient accounting, especially for services requiring QoS, as they often require separate AAA servers and facilities for network and service access, leading to limited service categories and increased complexity.

Innovation Solution

A network authentication, authorization, and accounting system that separates service and access servers, incorporating a service accounting server to manage service resource use and integrate accounting data with AAA servers, allowing for QoS guarantees and centralized accounting without the need for upgrading existing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate AAA servers are used for network access and service access, then QoS assurance can be provided, but system complexity increases and service categories are limited

Engineering Contradiction:
ImproveQoS assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the AAA server into two functional parts: a network AAA server for network access control and a service AAA server for service access control. This segmentation allows independent optimization of each function - the network AAA server ensures QoS for network resources while the service AAA server manages service-specific authentication and authorization, thereby maintaining QoS assurance without excessive overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the service AAA server queries authentication information from the network AAA server through a standardized interface. This intermediary approach allows service-level authentication to leverage network-level authentication results, avoiding redundant authentication processes while maintaining QoS control. The intermediary interface standardizes the interaction between different AAA servers, reducing integration complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If separate AAA servers are used for network and service access, then service-specific authentication can be achieved, but the number of facilities increases

Engineering Contradiction:
Improveservice-specific authenticationVSAvoidnumber of facilities
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent implements universality by designing the service AAA server to perform multiple functions: service authentication, service authorization, and service accounting. The service AAA server can serve different service types (VoIP, video conferencing, etc.) through a unified architecture, eliminating the need for separate dedicated facilities for each service type. This multi-functional design reduces the total number of facilities while maintaining service-specific authentication capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication functions of network access and service access into a coordinated system. The service AAA server combines service authentication with service authorization and accounting in a single facility, whereas traditionally separate facilities would be needed for each function. This merging reduces the quantity of facilities while maintaining the ability to provide service-specific authentication and control.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If traditional AAA architecture is used, then network access control is simplified, but service resource usage accounting becomes difficult

Engineering Contradiction:
Improvenetwork access controlVSAvoidservice resource usage accounting
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts the accounting function from the traditional AAA server and creates a dedicated service accounting server. This extraction allows the network AAA server to focus on network access control without being burdened by service-level accounting complexities. The service accounting server independently collects, stores, and manages service resource usage information, ensuring accurate accounting while keeping network access control simple and efficient.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary accounting data collection mechanism where the service AAA server acts as a mediator between service usage events and the accounting system. The service AAA server collects service resource usage information from various service platforms and transfers it to the service accounting server through standardized interfaces. This intermediary approach maintains the simplicity of network access control while enabling comprehensive service resource usage accounting.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7653933B2System and method of network authentication, authorization and accounting
Publication Date: 2010.01.26 HUAWEI TECH CO LTD
  • US7653933B2 patent drawing
  • US7653933B2 patent drawing
  • US7653933B2 patent drawing

AI summary

A network authentication, authorization and accounting system and a method thereof, wherein said system comprises: a subscriber device, via which a subscriber is connected with the network; an access server, connected with the subscriber device and designed to enable the subscriber device to access the network; an AAA server, connected with the access server and designed to collaborate with the access server to accomplish authentication, authorization, and accounting for the subscriber accessing the network; a service server, connected with the access server, designed to provide specific services, to exchange authentication and authorization information with the AAA server, and to interact with the subscriber device to provide the service; a service accounting server, connected with the service server, designed to collaborate with the service server to accomplish accounting for service resource use of the subscriber, and to send the accounting data to the AAA server. Accordingly, the present invention also discloses a network authentication, authorization and accounting method. The present invention enables a subscriber to access different types of services with only the subscriber identification information (user name and password) through a single identity authentication process, and supports centralized accounting.