AN-AAA Server Dual-Mode Authentication for HRPD Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing HRPD network faces challenges in supporting dual-mode terminals that require both CAVE and MD5 algorithms for authentication, as existing R-UIM cards only support CAVE, necessitating costly upgrades and inconvenient replacements, with no multi-mode R-UIM cards available.
Innovation Solution
The AN-AAA method allows HRPD network access authentication without modifying existing message streams or R-UIM cards, by determining terminal type and using either CAVE or MD5 algorithms based on NAI values, and sharing SSD_A between the HLR/AuC and AN-AAA via ANSI-41 messages, enabling dual-mode terminal authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing R-UIM cards are used in HRPD network, then CAVE algorithm authentication is supported, but MD5 algorithm authentication is not supported
Solution Approach 1:
The patent introduces an intermediary mechanism where the AN-AAA server acts as a mediator between the terminal and the authentication system. The server receives authentication requests, determines the terminal type based on NAI values, and selectively applies either CAVE or MD5 algorithms. This intermediary approach allows the system to support multiple algorithms without requiring terminals to have built-in support for both, thus resolving the contradiction between adaptability and device complexity.
Solution Approach 2:
The patent changes the parameter of algorithm selection from a fixed terminal-based decision to a dynamic server-based decision. By using NAI (Network Access ID) values to identify terminal types and dynamically selecting authentication algorithms at the AN-AAA server, the system achieves multi-algorithm support without modifying terminal hardware or software complexity. This parameter change resolves the contradiction by moving the complexity from the terminal device to the network server.
2Adaptability or versatility
If R-UIM cards are upgraded to support both CAVE and MD5 algorithms, then dual-mode terminal authentication is supported, but upgrade costs increase
Solution Approach 1:
The AN-AAA server serves as an intermediary that eliminates the need for expensive R-UIM card upgrades. Instead of modifying terminal hardware, the server handles algorithm selection and authentication processing, allowing existing R-UIM cards to continue functioning while enabling dual-mode authentication support in the network infrastructure.
Solution Approach 2:
The patent implements a virtual copy of the authentication functionality at the network level. Rather than physically upgrading R-UIM cards, the system creates a virtual authentication environment at the AN-AAA server that simulates multi-algorithm support, effectively copying the necessary authentication capabilities from the network side rather than requiring terminal-side hardware changes.
3Adaptability or versatility
If R-UIM cards are replaced with multi-mode cards, then both CAVE and MD5 algorithms are supported, but replacement inconvenience increases
Solution Approach 1:
The AN-AAA server acts as an intermediary that eliminates the need for physical card replacement. The server identifies terminal types through NAI values and automatically selects the appropriate authentication algorithm, allowing users to keep their existing R-UIM cards while still achieving multi-algorithm support without any replacement inconvenience.
Solution Approach 2:
Instead of requiring terminals to adapt to multiple algorithms through hardware changes, the patent inverts the approach by having the network adapt to different terminals. The AN-AAA server adjusts its authentication method based on the terminal type, reversing the traditional model where the terminal must support all required algorithms.
4Reliability
If HRPD network uses CHAP authentication with specified encryption algorithms, then authentication security is improved, but flexibility in algorithm selection is reduced
Solution Approach 1:
The patent changes the algorithm selection parameter from a fixed network-side decision to a dynamic decision based on terminal identification. By using NAI values to determine terminal type and subsequently selecting appropriate algorithms (CAVE for cdma2000/HRPD dual-mode terminals, MD5 for HRPD single-mode terminals), the system maintains strong security through protocol-compliant authentication while achieving flexibility in algorithm selection.
Solution Approach 2:
The authentication algorithm selection becomes dynamic rather than static. The AN-AAA server continuously adapts its authentication method based on real-time terminal identification through NAI values, allowing the system to maintain security requirements while flexibly selecting the most appropriate algorithm for each terminal type.
Data Source
AI summary
A method for Access Authentication in the High Rate Packet Data Network is proposed in the present invention comprising steps of the AN-AAA receiving the Radius Access Request message sent from the HRPD AN; the AN-AAA judging whether a terminal is a roaming one according to the Network Access ID and transmits the roaming terminal's authentication information to the terminal's home nerwork. If said terminal is a local one, the AN-AAA judges the type of the terminal according to the NAI value. If said terminal is a single-mode one, the AN-AAA works out the Result2 with the MD5 algorithm. if said terminal is in dual-mode, the AN-AAA calculates the Result2 with the CAVE algorithm to compare the Result1 with the Result2.


