Centralized Authentication Server for Multi-Operator PON Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-operator sliced telecommunications networks, the existing authentication methods for network termination nodes are inflexible and require operator-provided credentials, limiting the ability to share infrastructure among multiple operators and authenticate unknown devices, especially in PON-based broadband networks where device identities are unknown.

Innovation Solution

A method involving a provider federation operation that authenticates network termination nodes through a centralized server architecture, allowing multiple service providers to use the network infrastructure, and enabling detection and validation of untrusted devices by correlating their identity information with a specific service provider, decoupling the infrastructure provider from the service provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional authentication methods are used in multi-operator networks, then operator-provided credentials can authenticate known devices, but the system cannot authenticate unknown devices and infrastructure sharing among multiple operators is limited

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized authentication server as an intermediary between network termination nodes and service providers. This server stores credential information for multiple operators and performs authentication centrally, eliminating the need for each operator to implement separate authentication systems while maintaining security and flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server is designed to handle authentication requests from multiple different operators and device types universally. It can authenticate both known devices with pre-configured credentials and unknown devices through alternative verification methods, making the system adaptable to various operators and device scenarios without requiring operator-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If operator-specific credentials are required for authentication, then security can be maintained, but infrastructure sharing among multiple operators becomes difficult

Engineering Contradiction:
Improveauthentication securityVSAvoidinfrastructure sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges the authentication functions of multiple operators into a single centralized server. Instead of each operator maintaining separate credential verification systems, all operator credentials and authentication logic are consolidated in one secure location, enabling multiple operators to share the same physical infrastructure while maintaining individual security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized authentication server acts as a mediator between the shared physical infrastructure and multiple operators' security requirements. It translates diverse operator authentication policies into a unified verification process, allowing infrastructure sharing while preserving each operator's security standards through standardized credential validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If a centralized authentication system is implemented to enable multi-operator support, then infrastructure sharing is improved, but the system complexity increases

Engineering Contradiction:
Improvemulti-operator supportVSAvoidauthentication system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from individual operator equipment and relocates it to a dedicated centralized server. This separation allows the authentication logic to be independently managed, updated, and scaled without affecting the operational infrastructure, reducing the complexity burden on the overall network while maintaining multi-operator capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication system is segmented into distinct functional components: credential storage, authentication processing, and device management. This modular architecture allows each component to be developed, maintained, and scaled independently, reducing overall system complexity while enabling flexible multi-operator support through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11153369B2Operation of a telecommunications network being operated as a multi-operator sliced network
Publication Date: 2021.10.19 DEUTSCHE TELEKOM AG
  • US11153369B2 patent drawing
  • US11153369B2 patent drawing
  • US11153369B2 patent drawing

AI summary

A method for operation of a telecommunications network with a broadband access network includes: in a first step, a specific network termination node is connected to a specific line termination node and activated, wherein a walled garden access is provided, to the specific network termination node, to access a provider infrastructure control center of the telecommunications network; in a second step, subsequent to the first step, the walled garden access is used, by the specific network termination node or by a client device connected to the specific network termination node, to access a provider-specific server environment of the specific provider; and in a third step, subsequent to the second step, the specific network termination node is authenticated and federated with the specific provider.