Endpoint Node Authorization via Segmented Network Roles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for authorizing endpoint nodes for communication services lack flexibility, particularly in situations requiring separate device and service authorization, and do not allow for real-time updates or involvement of multiple responsible organizations.

Innovation Solution

A network system that separates device authorization from service authorization, allowing an operator network to perform device authentication and communicate with an organization network for service authorization, enabling flexible and updated authorization processes across home, visited, or transit networks and responsible organizations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If device authorization and service authorization are performed together in a single network, then the authorization process is simpler, but flexibility and real-time updates are limited

Engineering Contradiction:
Improveflexibility of service authorizationVSAvoidauthorization system structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the unified authorization process into two separate authorization operations: device authorization performed by the operator network and service authorization performed by the organization network. This segmentation allows each network to independently manage its specific authorization requirements, enabling flexible service authorization updates without affecting device authorization, thereby resolving the contradiction between flexibility and system complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a single network performs both device and service authorization, then the system is easier to manage, but real-time updates and multi-organization involvement are hindered

Engineering Contradiction:
Improveauthorization accuracyVSAvoidauthorization management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary communication mechanism between the operator network and organization network. The operator network acts as an intermediary that receives service authorization responses from the organization network and integrates them with device authorization results. This intermediary structure enables reliable multi-organization involvement and real-time updates while maintaining coordinated authorization management, resolving the contradiction between authorization accuracy and ease of management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If device authorization is separated from service authorization, then service authorization becomes more flexible, but the overall authorization process becomes more complex

Engineering Contradiction:
Improveservice authorization flexibilityVSAvoidauthorization processing structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization process into distinct device authorization and service authorization operations handled by different networks. This segmentation enables service authorization flexibility through independent organization network control while managing complexity through standardized inter-network communication protocols and clear role definitions between operator and organization networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal authorization framework where the operator network performs both device authorization and acts as an intermediary for service authorization, while the organization network provides service-specific authorization. This multi-functional design allows the system to handle both device and service authorization requirements universally, achieving flexibility without proportionally increasing processing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8086221B2Authorizing an endpoint node for a communication service
Publication Date: 2011.12.27 CISCO TECHNOLOGY INC
  • US8086221B2 patent drawing
  • US8086221B2 patent drawing
  • US8086221B2 patent drawing

AI summary

A network system for authorizing an endpoint node for a communication service includes an operator network and an organization network. The operator network operates to perform a device authorization operation to authorize the endpoint node for a communication session. The organization network operates to facilitate a service authorization operation to authorize the endpoint node for the communication service of the communication session.