Cross-Network UE Authorization Using Policy-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless networks face challenges in dynamically authenticating and authorizing User Equipment (UEs) associated with different home networks, particularly when these networks have differing authentication mechanisms and resource allocations, leading to inefficiencies and security risks.
Innovation Solution
Implementing a system that enables intercommunication between wireless networks to share authentication, authorization, and access policy information, allowing one network to leverage mechanisms from another to provide dynamic access control based on UE location, integrity, security risk, and role-based policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If wireless networks operate independently with separate authentication mechanisms, then each network can maintain its own security control, but interoperability and dynamic access control between networks becomes difficult
Solution Approach 1:
The patent introduces a policy control function as an intermediary that mediates between different wireless networks. This function receives access requests from one network, queries authentication and authorization policies from a policy database, and returns authorization decisions to the requesting network. This intermediary approach enables interoperability without requiring direct integration between all networks, thus reducing overall system complexity while maintaining security.
Solution Approach 2:
The patent creates a universal authentication and authorization framework that can serve multiple wireless networks with different home networks. The policy control function and database can handle authentication requests from various networks using different authentication mechanisms, providing a multi-functional system that simplifies interoperability without requiring network-specific dedicated systems.
2Reliability
If networks implement comprehensive authentication and authorization policies, then security control is improved, but processing time and authentication efficiency decreases
Solution Approach 1:
The patent implements preliminary action by pre-storing authentication and authorization policies in a policy database before actual access requests occur. The system pre-establishes access policies, authorized applications, and security parameters, so that when access requests arrive, the system only needs to query and match against pre-existing policies rather than performing comprehensive authentication in real-time, thus reducing processing time while maintaining security.
Solution Approach 2:
The system incorporates feedback mechanisms where authentication decisions and policy violations are recorded and fed back into the policy control function. This feedback allows the system to learn from previous authentication patterns and adjust future processing accordingly, potentially optimizing response times while maintaining robust security control through continuous policy enforcement.
3Adaptability or versatility
If networks share authentication and authorization information between different home networks, then dynamic access control capability is improved, but information security and data privacy risks increase
Solution Approach 1:
The patent applies local quality by allowing each network to maintain its own authentication mechanisms and security policies while sharing only necessary authorization information through the policy control function. Each network's specific authentication credentials and security parameters remain local and isolated, while a standardized authorization policy framework enables controlled information sharing for dynamic access control decisions, thus balancing capability enhancement with security risk mitigation.
Data Source
AI summary
A system described herein may receive, from a first User Equipment (“UE”) that is associated with a first network, a request to communicate with a second UE associated with a second network; receive, from the first network, UE information associated with the first UE; identify a particular access policy that is associated with the first UE and the second UE; and selectively grant or deny, based on the particular access policy and the UE information associated with the first UE, the request to communicate with the second UE. The first network may be a home network of the first UE, and the second network may be a home network of the second UE. The UE information may include location information, authentication information, or other monitored information associated with the first UE, as determined or provided by the first network.


