EAP-AKA Fast Re-authentication Identifier Session State Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
EAP-AKA's Fast Re-authentication mechanism increases load on HLR/HSS and requires AAA servers to store and replicate session state information, leading to high overhead and costs.
Innovation Solution
Using the Fast Re-authentication identifier as a session state store for key material, eliminating the need for AAA servers to store and replicate EAP-AKA key material for every session, and employing a server-key rotation mechanism synchronized with pseudonym identity regeneration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If Fast Re-authentication mechanism is implemented, then authentication efficiency is improved, but AAA server overhead and cost increase due to session state storage and replication
Solution Approach 1:
The patent extracts the session state storage function from the AAA server and relocates it to the client device. The AAA server only stores a reference identifier ( pseudonym) pointing to the client's stored session state, thereby eliminating the need for the AAA server to store and replicate actual session state information while maintaining fast re-authentication capability.
Solution Approach 2:
The patent introduces a pseudonym identifier as an intermediary between the AAA server and the actual session state stored on the client. This pseudonym allows the AAA server to reference client session state without directly storing or managing the session state itself, reducing server overhead while enabling fast re-authentication.
2Reliability
If session state information is replicated on backup AAA servers, then system reliability is improved, but storage overhead and cost increase
Solution Approach 1:
The patent extracts session state storage from centralized AAA servers (including backups) and places it on the client device. Backup AAA servers only need to store or reference the pseudonym identifier, not the actual session state, dramatically reducing storage requirements while maintaining reliability through pseudonym replication.
Solution Approach 2:
The patent uses lightweight pseudonym identifiers instead of heavy session state data for replication across backup servers. These pseudonyms are small, inexpensive to store and replicate, yet sufficient for maintaining system reliability and enabling session recovery if needed.
Data Source
AI summary
Systems and methods are described for improved authentication of subscribers wishing to connect to a wireless network using the EAP-AKA protocol. Embodiments exploit the requirement that the client store and transmit the Pseudonym and Fast Re-authentication Identities upon request. By using the Fast Re-authentication Identity to store session state key information, the need for the AAA server to store and replicate the EAP-AKA key information for every session is eliminated.


