Diameter Proxy Routing for Flexible NAS Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing 5G cellular networks face inflexibility and communication delays due to the need for pre-configuration of network access servers with fixed or dynamic IP addresses at the diameter routing agent (DRA) servers, which is exacerbated by the growing number of communication devices and the prevalence of spoofing attacks.

Innovation Solution

Implementing a proxy client, such as a firewall proxy or load balancer, between network access servers and DRA servers to manage IP address mappings and configuration, ensuring secure and efficient routing of Diameter messages through subnet masking and virtual IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network access servers are pre-configured with fixed or dynamic IP addresses at the diameter routing agent (DRA) servers, then network connectivity is established, but the system becomes inflexible and experiences communication delays when dealing with growing numbers of communication devices

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidcommunication delays
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent introduces a proxy server as an intermediary component between network access servers and the DRA. The proxy server receives Diameter messages from network access servers, performs IP address mapping to translate dynamic IP addresses to static proxy IP addresses, and forwards the translated messages to the DRA. This intermediary mechanism enables flexible adaptation to growing numbers of communication devices while maintaining efficient communication without requiring pre-configuration at the DRA for each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If pre-configuration is performed at the DRA for each network access server, then authentication is reliable, but the device complexity and infrastructure requirements increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication function for multiple network access servers into a single proxy server. Instead of configuring each network access server individually at the DRA, the proxy server consolidates the configuration with a single static IP address mapping. This merging approach maintains authentication reliability while significantly reducing device complexity and infrastructure requirements, as the proxy server handles authentication for all network access servers through centralized IP address translation.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If dynamic IP addresses are assigned to network access servers to accommodate growing user demands, then network scalability is improved, but security risks from spoofing attacks increase

Engineering Contradiction:
Improvenetwork scalabilityVSAvoidspoofing attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The proxy server acts as a security intermediary that validates IP address mappings before forwarding messages to the DRA. It maintains a mapping table that correlates dynamic IP addresses with authorized network access servers, performing verification to prevent spoofing attacks. This intermediary mechanism enables the network to scale with dynamic IP address assignment while enhancing security by filtering and validating addresses, thereby blocking spoofing attempts before they reach the authentication system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12549943B2Using a proxy in front of a diameter routing agent
Publication Date: 2026.02.10 T MOBILE INNOVATIONS LLC
  • US12549943B2 patent drawing
  • US12549943B2 patent drawing
  • US12549943B2 patent drawing

AI summary

A system comprises a network access server, a back-end network node, and a diameter routing agent (DRA). The network access server is configured to send, to the back-end network node, attribute-value pairs (AVP) of the network access server; receive, from a communication device, an authentication request; send, to the back-end network node, a Transmission Control Protocol (TCP) request responsive to receiving the authentication request; and send the authentication request to the DRA for authenticating a subscriber identity module (SIM) card. The back-end network node is coupled to the network access server and to the DRA, wherein the back-end network node is configured to send, to the DRA, configuration information for pre-configuring the network node at the DRA, and wherein the configuration information includes an IP address of the network node. The DRA coupled to the network node and configured to pre-configure the network node based on the configuration information.