EAP-AKA Fast Re-authentication Identifier Session State Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

EAP-AKA's Fast Re-authentication mechanism increases load on HLR/HSS and requires AAA servers to store and replicate session state information, leading to high overhead and costs.

Innovation Solution

Using the Fast Re-authentication identifier as a session state store for key material, eliminating the need for AAA servers to store and replicate EAP-AKA key material for every session, and employing a server-key rotation mechanism synchronized with pseudonym identity regeneration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If Fast Re-authentication mechanism is implemented, then authentication efficiency is improved, but AAA server overhead and cost increase due to session state storage and replication

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidAAA server overhead
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the session state storage function from the AAA server and relocates it to the client device. The AAA server only stores a reference identifier ( pseudonym) pointing to the client's stored session state, thereby eliminating the need for the AAA server to store and replicate actual session state information while maintaining fast re-authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a pseudonym identifier as an intermediary between the AAA server and the actual session state stored on the client. This pseudonym allows the AAA server to reference client session state without directly storing or managing the session state itself, reducing server overhead while enabling fast re-authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If session state information is replicated on backup AAA servers, then system reliability is improved, but storage overhead and cost increase

Engineering Contradiction:
Improvesystem reliabilityVSAvoidstorage overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts session state storage from centralized AAA servers (including backups) and places it on the client device. Backup AAA servers only need to store or reference the pseudonym identifier, not the actual session state, dramatically reducing storage requirements while maintaining reliability through pseudonym replication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses lightweight pseudonym identifiers instead of heavy session state data for replication across backup servers. These pseudonyms are small, inexpensive to store and replicate, yet sufficient for maintaining system reliability and enabling session recovery if needed.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8245039B2Extensible authentication protocol authentication and key agreement (EAP-AKA) optimization
Publication Date: 2012.08.14 AMDOCS DEV LTD
  • US8245039B2 patent drawing
  • US8245039B2 patent drawing
  • US8245039B2 patent drawing

AI summary

Systems and methods are described for improved authentication of subscribers wishing to connect to a wireless network using the EAP-AKA protocol. Embodiments exploit the requirement that the client store and transmit the Pseudonym and Fast Re-authentication Identities upon request. By using the Fast Re-authentication Identity to store session state key information, the need for the AAA server to store and replicate the EAP-AKA key information for every session is eliminated.