Access Network Proxy for Core Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication network protocols, such as IP, DHCP, MIP, and IGMP, face challenges in securing communication between access and core networks due to intelligence being distributed at end points and terminals, leading to high costs and security concerns, especially with shared data and control paths.
Innovation Solution
A method involving a trust server and EAP protocol to authenticate nodes within the communication network, ensuring secure communication by verifying previous authentication and location validation, thereby reducing dependency on terminal intelligence and simplifying security models.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If intelligence is placed in end points and terminals, then protocol functionality can be implemented, but cost of provisioning, maintaining, upgrading and guaranteeing security increases significantly
Solution Approach 1:
The patent extracts intelligence from end points and terminals by implementing a proxy mechanism in the access network. The proxy receives protocol messages from terminals, processes them locally, and forwards relevant information to the core network. This removes the burden of intelligence from customer devices while maintaining protocol functionality and security.
Solution Approach 2:
The patent introduces a proxy as an intermediary component between terminals and the core network. This proxy handles protocol intelligence locally in the access network, acting as a mediator that processes messages without requiring terminal involvement. The intermediary approach reduces provisioning costs while maintaining security through centralized control.
2Device complexity
If control plain shares the same data path as data plain, then network simplicity is maintained, but security and privacy concerns arise due to accessibility of control network elements to user traffic
Solution Approach 1:
The patent segments the network into distinct functional layers: access network with proxy for local processing, core network for centralized control, and authentication server for security verification. This segmentation separates control functions from data paths while maintaining overall network simplicity through modular architecture.
Solution Approach 2:
The proxy acts as an intermediary that isolates control network elements from direct user traffic access. By processing control messages locally and only forwarding necessary information to the core network, the proxy creates a security buffer that protects control elements while maintaining network simplicity.
3Reliability
If security mechanisms are implemented in access network, then security against untrusted terminals is improved, but dependency on terminal intelligence is reduced and complexity increases
Solution Approach 1:
The patent extracts security verification functionality from the terminal and places it in the access network proxy. The proxy performs authentication and authorization locally, then forwards only authenticated information to the core network. This removes security dependency from terminals while implementing robust security protection.
Solution Approach 2:
The access network proxy performs self-service security functions by locally verifying authentication tokens and processing security messages without requiring terminal involvement. The proxy autonomously handles security operations, reducing complexity by eliminating the need for complex terminal-based security models.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method of securing communication between an access network and a core network, wherein the access network and the core network are comprised in a communication network, wherein the access network comprises an agent, wherein the core network comprises a server and a trust server, and wherein the method comprises the step of receiving a request from the agent at the core network, wherein the request relates to a node which is served by the agent, wherein the request requests information about the node from the server. The method further comprises the step of requesting confirmation from the trust server if the node has been previously authenticated against the communication network and the step of sending the information requested from the server to the agent if the node has been previously authenticated against the communication network and the step of denying sending the information if the node has not been previously authenticated against the communication network. In other aspects, the invention relates to an access network, to a core network, to communication network component of the core network, to an agent and to a computer program product.