Telecommunications Network CPE Authentication via NASS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing telecommunications systems face inefficiencies in connecting customer premises equipment (CPE) to networks, including time-consuming configuration, insecure authentication, and limited plug-and-play capabilities due to reliance on untrusted environments for credential distribution and session establishment.

Innovation Solution

A method that establishes a physical communication channel between a telecommunications network and CPE using network access-related identification information, providing a public or private IP address for secure authentication through a Network Attachment Subsystem (NASS), allowing for efficient and secure access without pre-configured credentials, and enabling flexible service usage with varying functionality levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a polling system is used to manage network access, then network control is improved, but connection establishment time increases due to defined time periods when no network access is possible

Engineering Contradiction:
Improvenetwork controlVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing authentication mechanisms and session frameworks before actual network access is needed. The authentication server pre-processes credentials and the system maintains ready-state connections, allowing immediate network access without waiting for polling cycles or time-period allocations, thus resolving the contradiction between controlled access and connection speed.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If pre-configured credentials are distributed to customers, then authentication is enabled, but security deteriorates because credentials must be distributed in untrusted environments

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication server as an intermediary component that mediates between the CPE and the network. Instead of distributing credentials directly to customers or storing them in CPE, the authentication server acts as a trusted intermediary that receives authentication requests, verifies credentials securely, and issues authentication tokens. This intermediary approach enables authentication capability while eliminating the security vulnerability of distributing credentials in untrusted environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces the mechanical approach of physically distributing credentials to customers with a digital authentication mechanism. Instead of relying on physical credential distribution that must occur in untrusted environments, the patent uses digital authentication protocols where the authentication server verifies credentials remotely without requiring physical access or distribution in untrusted networks, thus maintaining ease of operation while improving security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If session-based IP address assignment is used, then network connectivity is established, but reliability deteriorates because the IP address cannot be used permanently requiring reconnection

Engineering Contradiction:
Improvenetwork connectivityVSAvoidconnection permanence
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The authentication server performs preliminary actions by establishing long-term authentication relationships and allocating persistent IP addresses during the initial authentication phase. Once authenticated, the system maintains the IP address assignment indefinitely without requiring periodic reconnection or session renewal, transforming the temporary session-based approach into a permanent connection while maintaining productivity.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If user-specific configuration profiles are assigned, then service customization is improved, but device complexity increases due to multiple configuration steps

Engineering Contradiction:
Improveservice customizationVSAvoidconfiguration process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication server performs preliminary actions by pre-configuring and storing user-specific profiles in advance. When a user authenticates, the server automatically retrieves and applies the corresponding pre-configured profile, eliminating the need for users to manually configure settings. This preliminary configuration approach enables service customization while reducing device complexity by automating the configuration process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service by having the authentication server automatically handle profile assignment and configuration based on the user's authentication credentials. Instead of requiring users to manually select or configure profiles, the system autonomously identifies the appropriate user-specific profile and applies it automatically, enabling service customization while simplifying the user experience and reducing configuration complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9332579B2Method and system for efficient use of a telecommunication network and the connection between the telecommunications network and a customer premises equipment
Publication Date: 2016.05.03 DEUTSCHE TELEKOM AG
  • US9332579B2 patent drawing
  • US9332579B2 patent drawing
  • US9332579B2 patent drawing

AI summary

A method for efficient establishing or configuring a connection between a telecommunications network and a customer premises equipment (CPE) via an access node includes: establishing a physical communication channel between the access; node of the telecommunications network and the CPE; providing a public or private Internet Protocol (IP) address to the CPE for use by the CPE to communicate with an IP Edge node of the telecommunications network; initially assigning a first functionality level to the public or private IP address; and assigning a second functionality level to the public or private IP address, when the telecommunications network is able to federate a network access related identification information to a contract related identification information.