Dual-Link Authentication for Roaming Voice Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, users face challenges in determining authorization and billing for voice communications over broadband networks, particularly when roaming, as existing systems lack efficient authentication mechanisms to ensure valid subscriptions and accurate charging.

Innovation Solution

Implementing a dual-authentication process where a user equipment (UE) first authenticates over a cellular link, generating an authentication key, and then uses this authentication information to authorize and bill voice communication sessions over a WLAN link, ensuring valid subscription association and proper billing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a UE engages in voice communications over broadband networks via WLAN access points, then communication capacity and bandwidth are improved, but authorization and billing control deteriorate due to lack of authentication mechanisms

Engineering Contradiction:
Improvecommunication capacityVSAvoidauthorization control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication over the cellular network before allowing WLAN communication sessions. The authentication key generated during cellular call setup is stored and later used to authorize WLAN sessions, ensuring authorization control is established in advance before broadband communication begins.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication key as an intermediary element that bridges the cellular network authentication and WLAN communication authorization. This key, generated during cellular call setup, serves as a mediator that enables the cellular network's authentication result to control WLAN session authorization without requiring direct integration between the networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate authentication is required for each communication link, then security and authorization precision are improved, but system complexity and user burden increase

Engineering Contradiction:
Improveauthorization precisionVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication key generated during cellular call setup serves multiple functions: it authenticates the UE for the cellular call, authorizes WLAN communication sessions, and enables billing control. This single authentication result is universally applied across different communication links (cellular and WLAN), eliminating the need for separate authentication processes while maintaining authorization precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the authentication processes of cellular and WLAN communications by using the same authentication key for both. The authentication result from the cellular network is combined with WLAN session authorization, creating a unified authentication mechanism that reduces complexity while maintaining security and billing control across multiple communication links.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10034168B1Authentication over a first communication link to authorize communications over a second communication link
Publication Date: 2018.07.24 SPRINT SPECTRUM LLC
  • US10034168B1 patent drawing
  • US10034168B1 patent drawing
  • US10034168B1 patent drawing

AI summary

Disclosed are a method, apparatus, and system for authenticating a communication session between a user equipment device (UE) and a communication network. A first authentication of a UE is performed by generating an authentication key, transmitting the authentication key over a first communication link from the UE to a communication network, authenticating the UE using the authentication key, and generating an authentication result indicative of authenticating the UE. A second authentication of the UE is performed to authorize a communication session over a second communication link between the UE and the communication network. The second authentication includes transmitting UE identifying information over the second communication link from the UE to the communication network and authenticating the UE using the UE identifying information and the authentication key. The second communication link is established under an internet protocol. After performing the second authentication, the communication session is authorized.