Distributed Authentication Caching IMS Network Elements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IMS and SIP-based systems face performance issues due to centralized authentication/identification and the lack of caching mechanisms for resources, leading to bottlenecks and scaling problems.
Innovation Solution
Network elements are pre-loaded with local user profiles to pre-authenticate SIP requests, allowing edge and switch nodes to cache resources based on user behavior and service requests, reducing the need for authentication and authorization to proceed to the core IMS network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized authentication and identification are used in IMS and SIP-based systems, then security and user management are maintained, but performance bottlenecks and scaling issues occur
Solution Approach 1:
The patent segments the centralized authentication function into distributed authentication components deployed at network edges and intermediaries. Local authentication databases are distributed to edge elements, allowing authentication to be performed locally rather than requiring all requests to reach the central HSS, thus maintaining security while improving performance
Solution Approach 2:
The patent implements pre-authentication mechanisms where user credentials are verified in advance before actual service requests are processed. This preliminary authentication action reduces the authentication overhead for subsequent requests, resolving the contradiction between maintaining security and improving system performance
2Device complexity
If centralized route engine and policy management are used, then network resource allocation is controlled, but bottlenecks and scaling problems arise
Solution Approach 1:
The patent divides the centralized route engine and policy management functions into distributed components deployed at multiple network locations including edges and intermediaries. This segmentation allows parallel processing of routing and policy decisions, increasing request processing capacity while maintaining the controlled allocation of network resources
Solution Approach 2:
The patent introduces a distributed architecture dimension to the traditionally centralized control plane. By deploying authentication and routing components across multiple spatial dimensions (central HSS, regional servers, edge elements), the system achieves both centralized policy control and distributed processing capacity
3Reliability
If no caching mechanisms are implemented for SIP requests, then real-time authentication is maintained, but bandwidth usage increases and lag occurs
Solution Approach 1:
The patent implements caching mechanisms that store pre-authenticated user credentials and session information. This preliminary caching action allows subsequent requests to be served from cache without requiring real-time authentication for each request, reducing processing lag while maintaining security through periodic cache validation
Solution Approach 2:
The patent creates local copies of authentication databases and user profile information at distributed network elements. These copies enable local authentication decisions without requiring constant communication with the central HSS, reducing bandwidth usage and processing lag while maintaining authentication reliability
Data Source
AI summary
Network elements in IMS or other SIP systems are configured to pre-authenticate SIP requests either as proxy or by snooping. One or more of these network elements are pre-loaded with a local database copy of the user profiles as typically contained in the HSS inside of the IMS control structures. A master database, such as the one typically contained in the HSS, is distributed to all network elements using database distribution methods. Advantageously, pre-authentication solves bottleneck issues in the SIP mechanism by allowing an end user device to use fully authenticated SIP requests. This prevents the requirement to perform authentication, authorization, and accounting (AAA) all the way back to the core IMS network, alleviating lag and scaling issues. Additionally, network elements including can become aware of the services requested through SIP requests, and track these requests for optimization. Specifically, resources requested based upon SIP requests can be cached.


