Authentication Signaling for Network Service Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current public or operator WLAN systems lack a dedicated signaling mechanism for setting up services between a WLAN terminal device and the WLAN network, preventing GPRS-type service selection and activation, which limits access to network services.

Innovation Solution

A method and system that uses an authentication message to signal service selection information via a first network to an authentication server of a second network, enabling connection to services indicated by the service selection information, employing Extensible Authentication Protocol (EAP) messages to facilitate service selection and connection establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If WLAN systems use generic authentication without dedicated service selection signaling, then authentication can be performed, but service selection and activation cannot be performed

Engineering Contradiction:
Improveservice selection capabilityVSAvoidsignaling mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication message is designed to serve multiple functions: it performs authentication verification while simultaneously conveying service selection information. This allows the existing authentication infrastructure to handle both authentication and service selection without requiring separate dedicated signaling mechanisms, thus improving adaptability while controlling complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines service selection information with the authentication message into a single signaling vehicle. By merging these two functions into one message exchange, the system enables service selection capability without proportionally increasing signaling complexity, as the service selection data is transported alongside authentication data in the same protocol exchange.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If WLAN systems implement dedicated service selection signaling, then service selection and activation can be performed, but the authentication process becomes more complex

Engineering Contradiction:
Improveservice selection capabilityVSAvoidauthentication process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication message structure is enhanced to carry both authentication credentials and service selection information simultaneously. This multi-functional approach allows the authentication process to handle service selection as a byproduct of the existing authentication exchange, avoiding the need for separate complex signaling procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Service selection information is conveyed during the authentication phase itself, before actual service connection is established. This preliminary action allows the network to pre-configure service parameters and select appropriate service nodes during authentication, simplifying the subsequent service activation process.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If WLAN systems use existing authentication protocols without service selection support, then authentication is simple, but access to specific network services is limited

Engineering Contradiction:
Improveauthentication simplicityVSAvoidservice access capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The authentication protocol is extended to perform multiple functions: standard authentication verification plus service selection. By making the authentication message multi-functional, the system maintains the simplicity of the original authentication flow while adding service access capability, allowing users to authenticate and select services in a single integrated process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication server acts as an intermediary that receives both authentication credentials and service selection information, processes them together, and returns appropriate service connection parameters. This intermediary approach allows the authentication process to seamlessly integrate service selection without complicating the user interface or client-side operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8233934B2Method and system for providing access via a first network to a service of a second network
Publication Date: 2012.07.31 NOKIA TECHNOLOGIES OY
  • US8233934B2 patent drawing
  • US8233934B2 patent drawing
  • US8233934B2 patent drawing

AI summary

The present invention relates to a method and system for providing access from a first network (30) to a service of a second network, wherein an authentication signaling is used to transfer a service selection information to the second network (70). Based on the service selection information, a connection can be established to access the desired service. Thereby, cellular packet-switched services can be accessed over networks which do not provide a context activation procedure or corresponding control plane signaling function.