Access Node Implicit Authentication IPv6 Subscriber Line

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DSL network architectures struggle to implement implicit user authentication based on subscriber line information in IPv6 networks, as they rely on stateless address allocation, which is not supported by prior art methods.

Innovation Solution

A network access method where an Access Node (AN) receives a request message from a User Equipment (UE), queries and obtains subscriber line information, and sends a second request message to a Broadband Network Gateway (BNG) that carries this information for access authentication, enabling implicit authentication through an Authentication, Authorization, and Accounting (AAA) server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If stateless address allocation is used in IPv6, then address exhaustion is avoided and scalability is improved, but implicit authentication based on subscriber line information cannot be implemented

Engineering Contradiction:
ImproveIPv6 address scalabilityVSAvoidauthentication capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism where the AN modifies Neighbor Solicitation messages to include subscriber line information, and the BNG acts as a mediator to extract this information and perform authentication via AAA server, thereby enabling authentication in stateless IPv6 environments without breaking the stateless address allocation model

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary authentication by modifying the Neighbor Solicitation message during the address resolution phase before actual data transmission begins, allowing authentication to be completed in advance using subscriber line information embedded in the IPv6 address allocation process

Inventive Principle:
Principle #10Preliminary action

2Reliability

If DHCP-based implicit authentication is used in IPv4, then user authentication is achieved, but the method is not applicable to stateless IPv6 address allocation

Engineering Contradiction:
Improveuser authenticationVSAvoidIPv6 compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameter carrier from DHCP messages to Neighbor Solicitation messages in IPv6, modifying the message structure to include subscriber line information in the Suffix Length and Interface ID fields, thereby adapting the authentication mechanism to work with IPv6's stateless address allocation while maintaining the implicit authentication concept

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of having the client request authentication separately as in traditional methods, the patent inverts the approach by embedding authentication information in the address resolution process itself, where the server (BNG) proactively extracts subscriber line information from the Neighbor Solicitation message and performs authentication, rather than waiting for a separate authentication request

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP2249538B1Method for accessing network, authentication method, communication system and related equipment
Publication Date: 2016.11.16 HUAWEI TECH CO LTD
  • EP2249538B1 patent drawingFigure 1
  • EP2249538B1 patent drawingFigure 2
  • EP2249538B1 patent drawingFigure 3

AI summary

A network access method, an authentication method, a communications system, and relevant devices are provided to support implicit authentication based on subscriber line information in Internet Protocol version 6 (IPv6). The network access method includes: receiving a first request message sent from a User Equipment (UE) on an Access Node (AN), where the first request message carries a Link-Local Address (LLA); obtaining subscriber line information corresponding to the UE; and sending a second request message from the AN to a Broadband Network Gateway (BNG), where the second request message carries the LLA and the subscriber line information and instructs the BNG to perform access authentication. An authentication method, a communications system and relevant devices are also disclosed.