Access Gateway Authentication Server Discovery via Unique Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of non-3GPP access networks and increased mobility of terminals between different operator domains lead to substantial signaling increases between anchor gateways, authentication servers, and HSS servers, causing network slowdowns and malfunctions due to frequent authentication server redirects.

Innovation Solution

A method where the access gateway receives a unique identifier of the authentication server from the authentication response, allowing it to directly register with the correct authentication server, eliminating the need for redirects and reducing signaling overhead by including this identifier in the authorization and connection requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the access gateway uses redirects to discover the authentication server identity, then the authentication process can handle multiple operators and mobility scenarios, but the signaling overhead increases substantially causing network slowdowns

Engineering Contradiction:
Improveauthentication server discovery capabilityVSAvoidnetwork processing speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The authentication server identity is determined in advance during the authentication phase and stored in the access gateway. When the anchor gateway needs to register, the pre-determined identity is directly used without requiring redirect signaling, thus eliminating the signaling overhead while maintaining adaptability to multiple operators and mobility scenarios

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If the anchor gateway contacts the default authentication server for registration, then the registration process can be simplified, but frequent redirects occur when the user has not been handled by this authentication server

Engineering Contradiction:
Improveregistration process complexityVSAvoidauthentication server redirection accuracy
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The access gateway receives feedback information (authentication server identity) from the authentication phase and uses this feedback to provide accurate registration information to the anchor gateway. This feedback mechanism ensures that the anchor gateway contacts the correct authentication server without needing redirects, improving reliability while keeping the registration process simple

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple authentication servers are deployed in a domain, then the system can handle user mobility between different operators, but the signaling between anchor gateways, authentication servers and HSS servers increases substantially

Engineering Contradiction:
Improveuser mobility handling capabilityVSAvoidsignaling overhead
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The authentication server identity information is extracted from the authentication response and passed to the access gateway. This extracted information is then used directly in the registration request to the anchor gateway, eliminating the need for HSS server involvement in the registration process and reducing signaling overhead while maintaining the ability to handle user mobility between multiple operators

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3332530B1Methods and devices for identifying an authentication server
Publication Date: 2019.12.04 ORANGE SA
  • EP3332530B1 patent drawingFigure 1~4
  • EP3332530B1 patent drawingFigure 2~5
  • EP3332530B1 patent drawingFigure 3~6

AI summary

A method for connecting a terminal of a user to an anchoring gateway connected to a packet-switching network. The method is implemented by an access gateway to which the terminal is connected and includes: transmission of a user authorization request, including an identifier of the user, to a current authentication server; receipt of a user authorization response from the current authentication server, including a unique identifier of an authentication server that authenticated the user; transmission of a connection request to the anchoring gateway, intended to connect the terminal to the packet-switching network, including the unique identifier of the authentication server that had authenticated the user.