Access Gateway Authentication Server Discovery via Unique Identifier
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of non-3GPP access networks and increased mobility of terminals between different operator domains lead to substantial signaling increases between anchor gateways, authentication servers, and HSS servers, causing network slowdowns and malfunctions due to frequent authentication server redirects.
Innovation Solution
A method where the access gateway receives a unique identifier of the authentication server from the authentication response, allowing it to directly register with the correct authentication server, eliminating the need for redirects and reducing signaling overhead by including this identifier in the authorization and connection requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the access gateway uses redirects to discover the authentication server identity, then the authentication process can handle multiple operators and mobility scenarios, but the signaling overhead increases substantially causing network slowdowns
Solution Approach 1:
The authentication server identity is determined in advance during the authentication phase and stored in the access gateway. When the anchor gateway needs to register, the pre-determined identity is directly used without requiring redirect signaling, thus eliminating the signaling overhead while maintaining adaptability to multiple operators and mobility scenarios
2Device complexity
If the anchor gateway contacts the default authentication server for registration, then the registration process can be simplified, but frequent redirects occur when the user has not been handled by this authentication server
Solution Approach 1:
The access gateway receives feedback information (authentication server identity) from the authentication phase and uses this feedback to provide accurate registration information to the anchor gateway. This feedback mechanism ensures that the anchor gateway contacts the correct authentication server without needing redirects, improving reliability while keeping the registration process simple
3Adaptability or versatility
If multiple authentication servers are deployed in a domain, then the system can handle user mobility between different operators, but the signaling between anchor gateways, authentication servers and HSS servers increases substantially
Solution Approach 1:
The authentication server identity information is extracted from the authentication response and passed to the access gateway. This extracted information is then used directly in the registration request to the anchor gateway, eliminating the need for HSS server involvement in the registration process and reducing signaling overhead while maintaining the ability to handle user mobility between multiple operators
Data Source
Figure 1~4
Figure 2~5
Figure 3~6
AI summary
A method for connecting a terminal of a user to an anchoring gateway connected to a packet-switching network. The method is implemented by an access gateway to which the terminal is connected and includes: transmission of a user authorization request, including an identifier of the user, to a current authentication server; receipt of a user authorization response from the current authentication server, including a unique identifier of an authentication server that authenticated the user; transmission of a connection request to the anchoring gateway, intended to connect the terminal to the packet-switching network, including the unique identifier of the authentication server that had authenticated the user.