Authentication and Authorization Function for Unsubscribed Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In next-generation mobile networks, there is a need to provide access to network resources for mobile devices without subscriptions, particularly in scenarios where emergency or non-emergency limited services are required, and existing technologies struggle to manage authentication and authorization across multiple administrative domains and virtual networks.

Innovation Solution

A method and system that utilize an authentication and authorization function (AAF) to authorize mobile devices to access limited access services, even if they fail to authenticate with primary virtual networks, by transmitting requests to third-party servers or core networks, allowing access to emergency or non-emergency services without a subscription, and enabling network providers to offer services through infrastructure providers and telecommunications connectivity service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a mobile device without a subscription attempts to access network resources, then access to network resources is denied, but the device cannot receive emergency or limited services

Engineering Contradiction:
Improveaccess to emergency servicesVSAvoidservice access for unsubscribed devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an Authentication and Authorization Function (AAF) as an intermediary entity that mediates between the mobile device and the core network. The AAF receives authentication requests from devices without subscriptions, performs authorization checks against multiple virtual networks, and grants limited access services when appropriate. This intermediary enables unsubscribed devices to access emergency and limited services while maintaining network security and control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the network requires authentication with primary virtual networks, then network security is maintained, but devices without subscriptions cannot access limited services

Engineering Contradiction:
Improvenetwork securityVSAvoidservice access procedure
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication and authorization process into distinct stages handled by the AAF. The AAF first performs authentication of the mobile device, then separately performs authorization checks against multiple virtual networks. This segmentation allows the system to maintain security requirements while providing flexible access decisions for devices without subscriptions, enabling them to receive limited services when authorization criteria are met.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the network uses traditional AAA (Authentication, Authorization, Accounting) frameworks, then service provider control is maintained, but MVNO customers cannot access services from other service providers

Engineering Contradiction:
Improveservice provider controlVSAvoidcross-provider service access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication and authorization framework where the AAF can authenticate devices and authorize access across multiple virtual networks and service providers. The system maintains control for each service provider while enabling MVNO customers to access services from other providers through the unified AAF interface. This multi-functional approach preserves provider control mechanisms while extending service accessibility across provider boundaries.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3292708B1Admission of an individual session in a network
Publication Date: 2021.04.07 HUAWEI TECH CO LTD
  • EP3292708B1 patent drawingFigure 1
  • EP3292708B1 patent drawingFigure 2
  • EP3292708B1 patent drawingFigure 3

AI summary

An aspect of the disclosure provides a method for session admission at a node in an infrastructure provider network. The method includes receiving a connection request from a user equipment not associated with a network with which the infrastructure provider network is associated and obtaining from the user equipment, an identification of a service provider with which the infrastructure provider network is associated. Access authorization is then requested from the identified service provider. Embodiments allow such a process to provide government mandated free access, or for some other service provider to pay for the service.