Backup System for Authentication Data Resilience in PLMN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Public Land Mobile Networks (PLMNs) with Data Layered Architecture, extreme failures of the Data Back End (Data-BE) lead to authentication data shortages, causing network flooding and security issues due to the inability to generate new authentication triplets or vectors, which are crucial for mobility management and user procedures.
Innovation Solution
A Backup system is introduced that stores subscriber authentication data and detects Data-BE failures, generating and rerouting authentication data sets to maintain network resilience, comprising interfaces for data exchange with Authentication Centre Front Ends and a processor for generating authentication data sets or vectors, ensuring continuous service during Data-BE unavailability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the Data Back End is designed to provide highly available and resilient service, then system reliability is improved, but the system becomes vulnerable to extreme failures that deplete authentication data
Solution Approach 1:
The invention pre-loads authentication data sets into the Data Back End before they are needed. When extreme failure occurs and authentication data is depleted, the system can immediately generate new authentication data without flooding the network, because the necessary credentials were prepared in advance and stored securely.
Solution Approach 2:
The system maintains a buffer or cushion of pre-generated authentication data sets in the Data Back End. This cushion allows the system to withstand extreme failures and continue providing authentication services without immediately depleting resources or triggering network flooding conditions.
2Reliability
If authentication data sets are continuously generated and stored, then authentication service availability is improved, but security risks increase due to potential data breaches
Solution Approach 1:
The authentication data is segmented into multiple separate data sets, each containing different credentials. Instead of storing all authentication data in a single vulnerable location, the system divides it across multiple secured instances in the Data Back End, reducing the impact of potential breaches while maintaining service continuity.
Solution Approach 2:
The system generates disposable, short-lived authentication data sets that are used once and then discarded. This approach allows continuous authentication service while minimizing security risks, as compromised data sets have limited utility and can be quickly replaced with new ones from the pre-loaded reservoir.
Data Source
AI summary
An apparatus configured to operate as a Backup system in a Data Layered Architecture Public Land Mobile Network. The apparatus comprises an interface for enabling a data exchange between the apparatus and a plurality of Authentication Centre Front Ends, and a memory for storing subscriber authentication data. The apparatus further comprises a processor for detecting a failure of a Data Back End and for receiving a redirected authentication data set request from an Authentication Centre Front End via the interface. The processor is further configured, in the event of a detected failure of Data Back End, to generate one or more authentication data sets in response to the request using the data stored in the memory, and send the generated data set(s) to the Authentication Centre Front End via the interface.


