Certificate-Based Network Session Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network session control methods fail to efficiently manage increasing network traffic and energy consumption, leading to inefficiencies in bandwidth utilization and energy costs, particularly in temporary networks like Software Defined Networking (SDN) and Network Function Virtualization (NFV).

Innovation Solution

A method and apparatus that allow direct control of network sessions by individual users through the use of certificates, where network entities retrieve and manage certificates based on provided services, enabling real-time monitoring and regulation of network load by adjusting the number of certificates, which correlates with energy consumption, thereby reducing energy usage and costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If bandwidth is increased by introducing fiber optics to handle increasing network traffic, then network capacity is improved, but infrastructure cost and complexity increase

Engineering Contradiction:
Improvenetwork capacityVSAvoidinfrastructure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent changes the parameter being controlled from physical bandwidth to virtual certificate-based access control. Instead of increasing physical infrastructure capacity, the system dynamically adjusts network access parameters through certificate issuance and retrieval, allowing flexible control of network session capacity without physical expansion

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates virtual copies of network access rights through certificates. Rather than physically expanding bandwidth infrastructure, the system uses digital certificate copies to control and manage network access, enabling multiple users to share existing physical infrastructure efficiently through virtualized access control

Inventive Principle:
Principle #26Copying

2Ease of operation

If more certificates are retrieved by network entities to enable direct user control, then user control capability is improved, but network traffic and processing load increase

Engineering Contradiction:
Improveuser control capabilityVSAvoidnetwork traffic
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent extracts the essential control function from complex network session management and concentrates it in certificate-based authentication. By taking out the core access control mechanism and embedding it in compact certificate structures, the system enables user control without proportionally increasing network traffic volume

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of having network entities generate and manage multiple complex session control messages, the patent inverts the approach by having users present pre-validated certificates that encapsulate all necessary authorization information. This reverses the control flow and reduces processing overhead

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP2942903B1Method for controlling a network session
Publication Date: 2020.02.12 ALCATEL LUCENT SA
  • EP2942903B1 patent drawingFigure 1
  • EP2942903B1 patent drawingFigure 2
  • EP2942903B1 patent drawingFigure 3

AI summary

The present invention is related to a process for controlling a network session, the network 1 comprising at least one user entity (11) and a group of one or more network entities (21, 22, 23, 26). The process comprises to provide by at least one of the group of network entities (21, 22, 23, 26) one or more services for the at least one user entity during the network session; and to transmit during the network session from the at least one user entity (11) a message (51) to at least one network entity of the group of network entities (21, 22, 23, 26), wherein the message (51) contains one or more certificates (511); and to retrieve one or more certificates (511) by at least one network entity of the group of network entities (21, 22, 23, 26) according to one or more of the provided services.