Bootstrapping Server Authorization for Roaming Mobile Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Facilitating authorization of a roaming mobile terminal is challenging due to the lack of access to authorization policies by visited network nodes, as these policies often reside in service-specific nodes on the home network without explicit roaming interfaces.

Innovation Solution

The system transfers security key-related policy information from the mobile terminal's home network to the visited network, using a bootstrapping server to include detailed authorization policy information in the user security settings package, which is processed by a policy decisioning server to modify and send to the service providing node for authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authorization policy information is stored only in service-specific nodes on the home network, then the home network can maintain detailed service-specific authorization policies, but visited network nodes cannot access this authorization policy information for roaming terminals

Engineering Contradiction:
Improveauthorization accuracyVSAvoidaccess to authorization policy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces the BSF as an intermediary component that receives authorization policy information from service-specific nodes on the home network and makes it accessible to visited network nodes. The BSF acts as a mediator that bridges the gap between home network policy storage and visited network authorization needs, allowing roaming terminals to be authorized without direct access to home network service-specific nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimensional layer to the authorization architecture by introducing the BSF as a separate authorization layer. Instead of visited nodes directly accessing home network service-specific nodes (horizontal dimension), the system creates a vertical dimension where the BSF receives policies from home network nodes and serves visited network nodes, transforming the authorization flow into a multi-layered structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If the bootstrapping server processes all authorization policy information, then comprehensive authorization can be provided, but the burden on the bootstrapping server increases

Engineering Contradiction:
Improveauthorization completenessVSAvoidbootstrapping server burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization processing function by separating policy information retrieval from authorization decision-making. The BSF retrieves and distributes authorization policy information from home network nodes, while visited network nodes perform the actual authorization decisions using this information. This segmentation reduces the computational burden on the BSF while maintaining comprehensive authorization capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by having the BSF pre-fetch and distribute authorization policy information to visited network nodes before actual authorization requests occur. This allows visited nodes to have authorization policies readily available, eliminating the need for the BSF to process every authorization request and reducing its ongoing burden.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authorization policy information is transferred to visited network nodes, then roaming terminal authorization can be facilitated, but network security requirements must be maintained

Engineering Contradiction:
Improveroaming authorizationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses copying by having the BSF receive authorization policy information from home network service-specific nodes and create copies for distribution to visited network nodes. Instead of establishing direct connections between visited nodes and home network nodes, the system creates secure copies of the necessary authorization information, reducing security risks associated with direct inter-network communication.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies local quality by allowing visited network nodes to store and use authorization policy information locally for making authorization decisions. Each visited node receives customized authorization information relevant to its specific context, rather than requiring all nodes to have access to all home network resources. This localized approach maintains security by limiting the scope of information exposure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2425644B1Systems, methods, and apparatuses for facilitating authorization of a roaming mobile terminal
Publication Date: 2017.11.22 NOKIA TECHNOLOGIES OY
  • EP2425644B1 patent drawingFigure 1
  • EP2425644B1 patent drawingFigure 2
  • EP2425644B1 patent drawingFigure 3

AI summary

Systems, methods, and apparatuses are provided for facilitating authorization of a roaming mobile terminal. A method may include receiving a request for security key related policy information for a user equipment device. The request may be sent by a service providing node on a visited network. The method may further include causing a service authorization information request including a user security settings package to be sent to a policy decisioning server. The method may also include receiving, in response to the service authorization information request, a service authorization information answer including a modified user security settings package including the authorization policy information for the user equipment device. The method may additionally include causing the requested security key related policy information to be sent to the service providing node. Corresponding systems and apparatuses are also provided.