Access Service Node User Identification via Virtual Access Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IP technology lacks effective tracking and tracing of users accessing public equipment networks, leading to security risks and difficulties in monitoring illegal activities due to ambiguity in identification and location, and fails to bind network layer IP with application layer services, compromising service security.

Innovation Solution

A method and system utilizing a Subscriber Identifier and Locator Separation Network (SILSN) where an Access Service Node (ASN) receives a network access request, verifies user credentials, and assigns a unique Access Identifier (AID) to the user, which is used as a virtual AID by public equipment for communication, establishing mapping relationships and tables to ensure secure and traceable access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional IP address technology is used for network access on public equipment, then users can access the network freely, but network supervision agencies cannot effectively track and trace users due to IP address ambiguity

Engineering Contradiction:
Improvenetwork access convenienceVSAvoiduser identification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the identification function from the location function by introducing a separate User Profile Identifier (UPI) that is independent of the IP address. The UPI is specifically designed for user identification and tracking, while the IP address continues to serve its traditional routing and location purposes. This segmentation allows users to access the network using public equipment without compromising supervision capabilities, as the UPI provides persistent user identification regardless of IP changes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a Network Access Server (NAS) as an intermediary component that bridges the gap between user authentication and network access. The NAS maintains the UPI and coordinates between the authentication system and the network infrastructure, enabling it to track and trace users effectively while allowing them to access public equipment without restriction. The NAS acts as the mediator that ensures both user convenience and supervisory effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional IP technology is used, then users can access application layer services on public equipment, but the binding of network layer IP and application layer services cannot be achieved, compromising service security

Engineering Contradiction:
Improveservice accessibilityVSAvoidservice binding security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing the UPI binding with application layer services during the network access authentication phase, before any actual service transactions occur. When a user authenticates through the NAS, the UPI is generated and bound to the user's service accounts in advance. This preliminary binding ensures that service security is maintained from the outset, allowing users to access services on public equipment while ensuring that the service provider can reliably identify and secure transactions with the correct user.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2512089B1Method and system for accessing network through public equipment
Publication Date: 2019.12.18 ZTE CORP
  • EP2512089B1 patent drawingFigure 1~2
  • EP2512089B1 patent drawingFigure 3
  • EP2512089B1 patent drawingFigure 4

AI summary

A method and system for accessing to a network through public equipment are provided in the invention. The method includes: after an access service node (ASN) receives a network access request message from a user on public equipment, the ASN sending the network access request message to an authentication center (AC), wherein, the network access request message comprises at least the user's account and password; the AC verifying validity of the account and the password, if the verification is passed, sending the user's access identifier (AID) to the ASN; and after the ASN receives said user's AID, the ASN sending the user's AID to the public equipment, the public equipment taking the user's AID as a virtual AID and using the virtual AID to send and receive user's messages. By the present invention, users who access to the network through the public equipment can be tracked and traced effectively.