Distributed Blacklist Management for IBC Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current centralized user authentication and management frameworks in mobile networks are not scalable and incur high costs, especially as the number of devices grows exponentially, necessitating a more efficient method for managing and distributing blacklists.

Innovation Solution

Implementing a distributed identity management and authentication framework based on Identity-Based Cryptography (IBC) that decentralizes authentication, utilizing multiple blacklist servers to manage and distribute User Equipment IDs (UE IDs), reducing the load on centralized systems and lowering operational costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a centralized authentication framework is used, then user management and authentication can be implemented, but the system becomes non-scalable and incurs high costs when the number of devices grows to 50-100 billion

Engineering Contradiction:
ImprovescalabilityVSAvoidcentralized system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized authentication system into multiple distributed authentication servers. Each server handles a portion of the authentication load and maintains local blacklist data, eliminating the single-point bottleneck and enabling the system to scale horizontally as device numbers increase to 50-100 billion.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional centralized architecture to a multi-dimensional distributed architecture where authentication servers are distributed across multiple nodes and locations. This dimensional expansion allows the system to handle vastly increased device counts without proportionally increasing central system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If a centralized server stores all user credentials and blacklist data, then authentication can be performed, but the storage and distribution costs increase significantly

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidblacklist storage and distribution cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the centralized blacklist storage into multiple distributed blacklist servers. Each authentication server maintains local blacklist data relevant to its jurisdiction or user group, reducing the amount of data that needs to be stored and distributed centrally while maintaining authentication reliability through distributed redundancy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by allowing each authentication server to maintain locally-relevant blacklist data rather than requiring all servers to store complete global blacklists. This reduces overall storage requirements and distribution costs while maintaining the ability to perform reliable authentication checks locally.

Inventive Principle:
Principle #3Local quality

3Productivity

If multiple blacklist servers are introduced to distribute the load, then scalability and cost are improved, but the system complexity increases

Engineering Contradiction:
Improveauthentication processing capacityVSAvoiddistributed system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing authentication servers that can perform multiple functions: authentication, blacklist maintenance, and inter-server communication. This multi-functionality reduces the need for specialized components and simplifies the overall distributed system architecture despite the increased number of servers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a standardized communication protocol as an intermediary layer between distributed authentication servers. This protocol mediates interactions between servers, managing the complexity of distributed operations while enabling high productivity through coordinated authentication processing across multiple nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3513538B1A blacklist management method for IBC-based distributed authentication framework
Publication Date: 2020.09.02 HUAWEI INT PTE LTD
  • EP3513538B1 patent drawingFigure 1
  • EP3513538B1 patent drawingFigure 2
  • EP3513538B1 patent drawingFigure 3

AI summary

This invention relates a system for managing and distributing of a blacklist of User Equipment ID (UE ID) in a network. The system comprises a number of groups of network,each of the groups of network comprise a blacklist server and a number of authentication servers. The system further comprises a Package Key Generator (PKG). The blacklist server is configured to: store a blacklist containing UE IDs that are not supposed to gain access to the network; transmit the blacklist to the plurality of authentication servers in the same group; receive a message; determine a content in the message is an order to add anew revoked UE ID in the blacklist; update the blacklist to include the new revoked UE ID;and send an update blacklist message to the plurality of authentication servers in the same group.