Backup System for Authentication Data Resilience in PLMN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Public Land Mobile Networks (PLMNs) with Data Layered Architecture, extreme failures of the Data Back End (Data-BE) lead to authentication data shortages, causing network flooding and security issues due to the inability to generate new authentication triplets or vectors, which are crucial for mobility management and user procedures.

Innovation Solution

A Backup system is introduced that stores subscriber authentication data and detects Data-BE failures, generating and rerouting authentication data sets to maintain network resilience, comprising interfaces for data exchange with Authentication Centre Front Ends and a processor for generating authentication data sets or vectors, ensuring continuous service during Data-BE unavailability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the Data Back End is designed to provide highly available and resilient service, then system reliability is improved, but the system becomes vulnerable to extreme failures that deplete authentication data

Engineering Contradiction:
Improveauthentication data availabilityVSAvoidnetwork flooding
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The invention pre-loads authentication data sets into the Data Back End before they are needed. When extreme failure occurs and authentication data is depleted, the system can immediately generate new authentication data without flooding the network, because the necessary credentials were prepared in advance and stored securely.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains a buffer or cushion of pre-generated authentication data sets in the Data Back End. This cushion allows the system to withstand extreme failures and continue providing authentication services without immediately depleting resources or triggering network flooding conditions.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If authentication data sets are continuously generated and stored, then authentication service availability is improved, but security risks increase due to potential data breaches

Engineering Contradiction:
Improveauthentication service continuityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The authentication data is segmented into multiple separate data sets, each containing different credentials. Instead of storing all authentication data in a single vulnerable location, the system divides it across multiple secured instances in the Data Back End, reducing the impact of potential breaches while maintaining service continuity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system generates disposable, short-lived authentication data sets that are used once and then discarded. This approach allows continuous authentication service while minimizing security risks, as compromised data sets have limited utility and can be quickly replaced with new ones from the pre-loaded reservoir.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS9639440B2Authentication in a data layered architecture network
Publication Date: 2017.05.02 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9639440B2 patent drawing
  • US9639440B2 patent drawing
  • US9639440B2 patent drawing

AI summary

An apparatus configured to operate as a Backup system in a Data Layered Architecture Public Land Mobile Network. The apparatus comprises an interface for enabling a data exchange between the apparatus and a plurality of Authentication Centre Front Ends, and a memory for storing subscriber authentication data. The apparatus further comprises a processor for detecting a failure of a Data Back End and for receiving a redirected authentication data set request from an Authentication Centre Front End via the interface. The processor is further configured, in the event of a detected failure of Data Back End, to generate one or more authentication data sets in response to the request using the data stored in the memory, and send the generated data set(s) to the Authentication Centre Front End via the interface.