Distributed Authentication Nodes for Single-Point Failure Resilience

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Authentication and Key Agreement (AKA) mechanism in communication networks is vulnerable to failures of the Home Location Register (HLR)/Home Subscriber Server (HSS) and is not applicable to Peer to Peer (P2P) distributed network environments, leading to authentication failures when the single authentication server fails.

Innovation Solution

A Distributed Service Network (DSN) authentication system using Super Node-Core (SN-C) nodes that store and authenticate user information in a distributed manner, allowing authentication information to be requested and stored across multiple nodes to ensure availability and reduce the risk of authentication failures, with the number of hops between nodes optimized to maintain authentication within the allowed time delay.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information is stored on a single HLR/HSS, then the authentication process is simple and centralized, but the system reliability decreases and authentication fails when the single server fails

Engineering Contradiction:
Improveauthentication availabilityVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized authentication function into multiple distributed SN-C nodes. Each node stores authentication information for specific users, and the system divides user authentication responsibilities across multiple nodes rather than relying on a single HLR/HSS. This segmentation provides redundancy and ensures authentication continuity when individual nodes fail.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the structural parameter of the authentication system from centralized to distributed architecture. By transforming the single-point authentication model into a multi-node distributed model, the system achieves improved reliability while managing complexity through standardized node interfaces and protocols.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If authentication information is distributed across multiple SN-C nodes, then system reliability and availability improve, but the complexity of requesting and managing authentication information increases

Engineering Contradiction:
Improveauthentication availabilityVSAvoidauthentication information request process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary mechanism where SN-C nodes communicate through standardized interfaces and protocols. When a user accesses the network, the system uses user identifiers and node information to locate the appropriate authentication data, simplifying the process of retrieving authentication information from distributed nodes without requiring complex direct access to each node.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Each SN-C node is designed with universal functionality to handle authentication requests for multiple users. The nodes can both store authentication information and process authentication requests, eliminating the need for specialized dedicated servers for each function and simplifying the overall operational complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If authentication information is stored on remote SN-C nodes, then system distribution and reliability improve, but authentication time delay increases

Engineering Contradiction:
Improveauthentication availabilityVSAvoidauthentication time delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-distributing authentication information across multiple SN-C nodes before it is needed. User authentication data is proactively stored on multiple nodes in advance, so when authentication is required, the information is already available locally or can be quickly retrieved from nearby nodes, reducing access time delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies local quality by optimizing the distribution of authentication information so that frequently accessed user data is stored on locally accessible SN-C nodes. The system prioritizes storing authentication information on nodes that are geographically or network-wise closer to user access points, reducing transmission delays while maintaining distribution benefits.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8763083B2Method, super node-core (SN-C) node and system for requesting and storing distributed service network (DSN) authentication information
Publication Date: 2014.06.24 CHINA MOBILE COMM GRP CO LTD
  • US8763083B2 patent drawing
  • US8763083B2 patent drawing
  • US8763083B2 patent drawing

AI summary

A method, Super Node-Core (SN-C) node and Distributed Service Network (DSN) authentication system for requesting and storing DSN authentication information are provided, wherein the method for requesting the DSN authentication information includes: according to a user access request, judging whether a local SN-C node stores the authentication information of the user; when the local SN-C node stores the authentication information, initiating an authentication process directly; when the local SN-C node does not store the authentication information, requesting the authentication information from other SN-C nodes which store the authentication information of the user. The method, SN-C node and DSN authentication system for requesting and storing the DSN authentication information, by means of the distributed storage and authentication of the authentication information of the user, can acquire the authentication information from other SN-C nodes when a failure occurs in one of the SN-C nodes, and reduce the risk that a single authentication server is unable to perform the authentication and operation caused by the failure.