Authentication Ticket Service Levels for Fair IoT Resource Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of IoT devices competing for limited network resources leads to inefficient and unfair allocation, affecting the service quality and performance of IoT devices.

Innovation Solution

A telecommunications system that employs an authentication server to generate encrypted levels of service with corresponding encryption keys, allowing servers to assess and provide services based on specific performance requirements, ensuring fair and efficient resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple IoT devices connect to the network simultaneously, then the network coverage and device connectivity increase, but the network resource competition intensifies and service quality deteriorates

Engineering Contradiction:
Improvedevice connectivityVSAvoidservice quality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments network resources into multiple levels (first level, second level, third level) with different performance requirements and encryption keys. This segmentation allows the system to allocate resources differently to various IoT devices based on their specific needs, preventing resource contention from degrading overall service quality while maintaining high device connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different encryption keys and performance requirements to different levels of service. Each level has customized resource allocation parameters, allowing the system to optimize service quality for specific device types or applications while maintaining broad network coverage for diverse IoT devices.

Inventive Principle:
Principle #3Local quality

2Productivity

If network resources are allocated without encryption protection, then the resource allocation process is simplified and faster, but the security and fairness of resource allocation is compromised

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidallocation fairness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-generating multiple encryption keys and associating them with different service levels before resource allocation occurs. The authentication server prepares the encrypted performance requirements and corresponding keys in advance, allowing for secure and efficient resource allocation without compromising fairness, as the encryption framework is already in place to ensure equitable distribution.

Inventive Principle:
Principle #10Preliminary action

3Speed

If the authentication server provides all encryption keys to servers simultaneously, then the service provisioning process is accelerated, but the ability to enforce differentiated service levels is reduced

Engineering Contradiction:
Improveservice provisioning speedVSAvoidservice level differentiation
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the provision of encryption keys conditional and dynamic rather than static and simultaneous. The authentication server provides encryption keys to servers on-demand based on the specific service level being provisioned. This dynamic approach maintains fast service provisioning while preserving the ability to enforce differentiated service levels, as keys are released only when needed for specific authentication scenarios.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4564740B1A telecommunications system and a method of operating the telecommunications system
Publication Date: 2026.02.11 BRITISH TELECOM PLC
  • EP4564740B1 patent drawingFigure 1
  • EP4564740B1 patent drawingFigure 2

AI summary

A method (200) of operating a telecommunications system (100), said system comprising a/an: client device (110); set of servers (130) for providing a service to the client device; and authentication server (120) for generating an authentication ticket for provision of the service by the set of servers to the client device; the method comprising the steps of: generating at the authentication server: a set of encrypted levels of service (220), said set comprising at least two different levels of service, each of said levels: comprising a performance requirement; and being encrypted with a corresponding encryption key from a set of encryption keys; and an authentication ticket, for the client device and service, said ticket comprising the set of encrypted levels of service; communicating, to the set of servers; the authentication ticket (230); and performing a process comprising the steps of: communicating, to the set of servers, an encryption key, from the set of encryption keys, not yet having been communicated to the set of servers (240); processing, by the set of servers, the authentication ticket using said communicated encryption key, thereby to retrieve the performance requirement within the corresponding level of service (250); determining, by the set of servers, whether to provide the service in accordance, at least, with the retrieved performance requirement (250); and subsequent to said determining, identifying that provision of the service according to, at least, the retrieved performance requirement is (260): rejected by the set of servers (260-1), in response to which subsequently reiterating the process (240); or accepted by at least one of the servers (260-2), in response to which subsequently selecting one of said servers to provide the service according to, at least, the retrieved performance requirement (280).