Auto-Discovery of Non-Public Network Addresses for Base Stations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile network base transceiver stations (BTS) face challenges in securely connecting to a packet data network without requiring separate provisioning and exposing critical information to potential abuse or denial of service attacks.
Innovation Solution
Implementing an auto-discovery process where BTS registers with a registration server to obtain the IP address of an aggregation gateway, using a secure connection and mutual authentication to protect against denial of service attacks, and eliminating the need for each BTS to be separately provisioned with network information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If BTS is separately provisioned with packet data network address information, then connection reliability is improved, but device complexity and provisioning burden increase
Solution Approach 1:
The BTS performs automatic self-provisioning by discovering the packet data network address through listening to broadcast messages or querying a registration server, eliminating the need for manual configuration and reducing provisioning complexity while maintaining connection reliability
Solution Approach 2:
The system performs preliminary address discovery and registration before the BTS needs to establish data connections, so that when connections are required, the address information is already available, simplifying the connection establishment process
2Ease of operation
If packet data network address information is made publicly accessible, then ease of operation is improved, but security and vulnerability to attacks worsen
Solution Approach 1:
A registration server acts as an intermediary between BTS and the packet data network address information. The BTS queries the registration server to obtain the address, which is not directly exposed to the public network, thereby maintaining ease of address discovery while reducing vulnerability to attacks
Solution Approach 2:
The critical address information is extracted from the public broadcast domain and placed in a protected registration server. Only authenticated BTS can obtain this information through controlled queries, separating the public discovery process from the sensitive information storage
Data Source
AI summary
Providing a network address is disclosed. A communication indicating that a first node desires to communicate via a packet data network with a second node configured to provide access to a private resource is received. A non-publicly advertised packet data network address usable to communicate with the second node via the packet data network is provided to the first node.


