Authentication Server Identifier for Roaming Signaling Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In non-3GPP access networks, the frequent mobility of terminals between different operator domains and the increase in authentication servers lead to substantial signaling overhead, causing slowdowns and malfunctions due to the need for anchor gateways to discover and redirect registration requests through multiple authentication servers.

Innovation Solution

A method where the access gateway receives a unique identifier of the authentication server from the authentication response, allowing it to directly register with the correct authentication server, thereby avoiding unnecessary signaling and redirections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the anchor gateway discovers the authentication server identity through static configuration or DNS interrogation, then the system can handle terminal mobility between different operator domains, but substantial signaling overhead is generated causing network slowdowns and malfunctions

Engineering Contradiction:
Improveterminal mobility between operator domainsVSAvoidnetwork efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The authentication server identity is determined in advance during the terminal authentication phase. The access gateway receives the authentication server identity from the authentication server when the terminal attaches to the network, so that when the anchor gateway needs to register, the correct server identity is already known without requiring discovery or redirection procedures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access gateway acts as an intermediary that receives and forwards the authentication server identity to the anchor gateway. This intermediary mechanism ensures that the anchor gateway obtains the correct authentication server identity without generating additional signaling overhead for discovery or redirection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the anchor gateway sends registration requests through default authentication servers, then the system can handle roaming scenarios, but multiple redirections through HSS server are required increasing signaling complexity

Engineering Contradiction:
Improveroaming scenario handlingVSAvoidsignaling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The correct authentication server identity is determined in advance during terminal authentication. The access gateway stores this identity and provides it to the anchor gateway, eliminating the need for default server attempts and subsequent redirections through HSS

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server identity information is extracted from the authentication process and separately provided to the anchor gateway. This extraction removes the need for the anchor gateway to go through the complex redirection process involving default servers and HSS queries

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10856145B2Method and device for identifying visited and home authentication servers
Publication Date: 2020.12.01 ORANGE SA
  • US10856145B2 patent drawing
  • US10856145B2 patent drawing
  • US10856145B2 patent drawing

AI summary

Authentication problems often occur when a user of a terminal visits a communications network while roaming. A method is therefore provided for authorizing an authenticated user of a communications terminal. The terminal is configured to connect to a packet-switching network via an access gateway over a current network to which the terminal is connected. The method is implemented by a current authentication server over the current network and includes: receipt of a user authorization request from the access gateway, including an identifier of the user; transmission of a user authorization response to the access gateway, including parameters for authorizing the user, and a unique identifier of an authentication server that authenticated the user.