Access Controller Roaming Wi-Fi Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In fixed communication networks, providing roaming Wi-Fi access for mobile users while ensuring secure communication and controlling costs is challenging, especially when the home gateway is not owned by the IP network service provider.
Innovation Solution
A system comprising an access controller and an authentication, authorization, and accounting proxy, which establishes secure tunnels between the user equipment and the network access server, allowing the IP Edge to control and account for communications without trusting the home gateway, using Pairwise Master Keys and protocols like CAPWAP and RADIUS for authentication and accounting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the UE establishes trust with the HG for wireless access, then roaming access is provided, but the UE communications may be intercepted at the HG or home network
Solution Approach 1:
The patent introduces an Access Controller (AC) as an intermediary component that mediates between the UE and HG. The AC establishes a secure tunnel with the UE independently of the HG, allowing the UE to access the network through the HG without trusting the HG with communication security. This intermediary structure enables roaming access while preventing interception by the HG.
2Ease of operation
If the HG controls communications for authentication and accounting, then roaming access is managed, but charging the HG may not be desired or beneficial to the IP network service provider
Solution Approach 1:
The Access Controller (AC) serves as an intermediary that centralizes authentication and accounting control functions. Instead of the HG controlling communications, the AC handles authentication requests and accounting operations, allowing the IP network service provider to maintain control without requiring the HG to be charged for these services. This resolves the cost control issue while preserving communication management capabilities.
3Ease of operation
If the UE communicates with the IP network via the HG, then wireless access is provided, but the HG must be trusted with the communications
Solution Approach 1:
The patent introduces a secure tunnel established between the UE and AC that operates independently of the HG trust relationship. The AC acts as a mediator that the UE can trust directly, bypassing the need to trust the HG with communications. The HG remains involved in forwarding traffic but is excluded from the security trust chain, allowing wireless access without the trust requirement.
Data Source
AI summary
An apparatus comprising a node comprising an access controller (AC) and an authentication, authorization and accounting (AAA) proxy (AAA-P), wherein the AC is configured to manage authentication for a user equipment (UE), and wherein the AAA-P is configured to exchange authentication information related to the UE with an AAA server. Included is a network component comprising at least one processor configured to implement a method comprising establishing a first tunnel with a home gateway (HG), wherein the HG communicates wirelessly with a UE, and establishing a second tunnel between the UE and a Network Access Server (NAS). Also included is a network component comprising at least one processor configured to implement a method comprising receiving a Pairwise Master Key (PMK) from an AAA mediator (AAA-M), and authenticating a UE using the PMK.


