Access Network Proxy for Core Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication network protocols, such as IP, DHCP, MIP, and IGMP, face challenges in securing communication between access and core networks due to intelligence being distributed at end points and terminals, leading to high costs and security concerns, especially with shared data and control paths.

Innovation Solution

A method involving a trust server and EAP protocol to authenticate nodes within the communication network, ensuring secure communication by verifying previous authentication and location validation, thereby reducing dependency on terminal intelligence and simplifying security models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If intelligence is placed in end points and terminals, then protocol functionality can be implemented, but cost of provisioning, maintaining, upgrading and guaranteeing security increases significantly

Engineering Contradiction:
Improveprotocol deployment costVSAvoidsecurity guarantee
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent extracts intelligence from end points and terminals by implementing a proxy mechanism in the access network. The proxy receives protocol messages from terminals, processes them locally, and forwards relevant information to the core network. This removes the burden of intelligence from customer devices while maintaining protocol functionality and security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a proxy as an intermediary component between terminals and the core network. This proxy handles protocol intelligence locally in the access network, acting as a mediator that processes messages without requiring terminal involvement. The intermediary approach reduces provisioning costs while maintaining security through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If control plain shares the same data path as data plain, then network simplicity is maintained, but security and privacy concerns arise due to accessibility of control network elements to user traffic

Engineering Contradiction:
Improvenetwork structure simplicityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network into distinct functional layers: access network with proxy for local processing, core network for centralized control, and authentication server for security verification. This segmentation separates control functions from data paths while maintaining overall network simplicity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy acts as an intermediary that isolates control network elements from direct user traffic access. By processing control messages locally and only forwarding necessary information to the core network, the proxy creates a security buffer that protects control elements while maintaining network simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security mechanisms are implemented in access network, then security against untrusted terminals is improved, but dependency on terminal intelligence is reduced and complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity model complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts security verification functionality from the terminal and places it in the access network proxy. The proxy performs authentication and authorization locally, then forwards only authenticated information to the core network. This removes security dependency from terminals while implementing robust security protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access network proxy performs self-service security functions by locally verifying authentication tokens and processing security messages without requiring terminal involvement. The proxy autonomously handles security operations, reducing complexity by eliminating the need for complex terminal-based security models.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP1843541B1A method of securing communication between an access network and a core network
Publication Date: 2010.02.24 ALCATEL LUCENT SA
  • EP1843541B1 patent drawingFigure 1
  • EP1843541B1 patent drawingFigure 2

AI summary

The invention relates to a method of securing communication between an access network and a core network, wherein the access network and the core network are comprised in a communication network, wherein the access network comprises an agent, wherein the core network comprises a server and a trust server, and wherein the method comprises the step of receiving a request from the agent at the core network, wherein the request relates to a node which is served by the agent, wherein the request requests information about the node from the server. The method further comprises the step of requesting confirmation from the trust server if the node has been previously authenticated against the communication network and the step of sending the information requested from the server to the agent if the node has been previously authenticated against the communication network and the step of denying sending the information if the node has not been previously authenticated against the communication network. In other aspects, the invention relates to an access network, to a core network, to communication network component of the core network, to an agent and to a computer program product.