Authentication Server Signalling Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication protocols in cellular and Internet networks face inefficiencies in roaming scenarios, particularly in heterogeneous access domains, where home domains must blindly trust visited domains, leading to sub-optimal performance and potential financial insecurity due to high signalling overhead and lack of control over authentication processes.
Innovation Solution
A server-based system that dynamically determines whether authentication should be handled by the home domain or the visited domain, optimizing signalling routes and maintaining financial security by generating and sending authentication data as needed, and allowing for delegation and revocation of authentication responsibilities based on client subscription and network properties.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the home domain performs authentication for every client access attempt in visited domains, then authentication security is improved, but signalling overhead and processing time increase
Solution Approach 1:
The home domain performs authentication in advance when the client first accesses the visited domain, stores the authentication result and session key locally at the visited domain authenticator, and reuses this stored information for subsequent access attempts. This preliminary authentication action eliminates the need for repeated authentication signalling between home and visited domains, reducing signalling overhead while maintaining security.
Solution Approach 2:
The patent implements local authentication capability at the visited domain authenticator by storing authentication credentials and session keys locally. This allows the visited domain to perform autonomous authentication decisions for subsequent access attempts without contacting the home domain, thereby reducing signalling overhead while maintaining authentication security through locally stored verified credentials.
2Productivity
If the visited domain performs local authentication without home domain involvement, then authentication efficiency is improved, but the home domain loses control and must blindly trust the visited domain
Solution Approach 1:
The home domain performs authentication in advance and provides authentication vectors to the visited domain, enabling the visited domain to perform efficient local authentication. This preliminary action by the home domain ensures control and trustworthiness, while the subsequent local authentication at the visited domain improves efficiency by avoiding repeated home domain contact.
Solution Approach 2:
The patent introduces authentication vectors as an intermediary mechanism that carries authentication credentials from the home domain to the visited domain. These vectors enable the visited domain to perform local authentication independently, improving efficiency, while the home domain maintains control by generating and managing these authentication vectors that contain verified credentials.
3Loss of time
If authentication vectors are cached at the visited domain for multiple accesses, then signalling overhead is reduced, but the authentication system becomes more complex
Solution Approach 1:
The home domain provides authentication vectors in advance that contain all necessary credentials for multiple subsequent authentications. The visited domain caches these pre-provided vectors locally, enabling rapid authentication without repeated signalling to the home domain. This preliminary provision of authentication vectors reduces signalling overhead while the caching mechanism adds manageable complexity only at the visited domain.
Solution Approach 2:
The patent implements selective caching of authentication vectors specifically at the visited domain authenticator, allowing local storage and reuse of authentication credentials. This local caching reduces the need for repeated authentication signalling, and the complexity is confined to the visited domain's authentication module rather than affecting the entire authentication system architecture.
Data Source
AI summary
A server in a home domain for managing the authentication of clients that are subscribers of the home domain, but are attached to a visited domain. Based on knowledge of the type of security being used in an access network of the visited domain, the server determines whether a given client is to be authenticated by the visited domain or the home domain. The server then signals the result to the visited domain.


