Dynamic External UE Authorization Through Cross-Network Roaming Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless networks face challenges in efficiently authenticating and authorizing User Equipment (UEs) associated with different networks, particularly when these networks have differing authentication mechanisms and resource allocations, leading to inefficiencies in dynamic access control.
Innovation Solution
A system that enables intercommunication between wireless networks to authenticate UEs by leveraging authentication mechanisms, authorization mechanisms, location determination, and device status from both networks, using systems like authentication and authorization systems, device integrity systems, and security risk measurement systems to dynamically control access based on access policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each wireless network maintains separate authentication and authorization mechanisms, then network security and control are improved, but system complexity and interoperability challenges increase
Solution Approach 1:
The patent introduces a roaming network as an intermediary entity that facilitates authentication and authorization between UEs of different networks. The roaming network receives authentication requests from a first network, obtains necessary information from a second network, and makes authorization decisions, thereby enabling secure inter-network communication without requiring direct trust between all networks.
Solution Approach 2:
The authentication and authorization system is designed to handle multiple network types and scenarios universally. The system can authenticate UEs from different home networks, apply different authorization policies based on network type and UE characteristics, and maintain consistent security practices across diverse network environments.
2Productivity
If dynamic access control is implemented based on real-time network conditions, then access efficiency and optimization are improved, but authentication time and processing delay increase
Solution Approach 1:
The system performs preliminary authentication of the UE with the home network before the actual access request is processed. Network capabilities and UE information are obtained in advance, allowing the roaming network to make informed authorization decisions faster when access requests arrive, thus reducing overall authentication time.
Solution Approach 2:
The authorization decision is made dynamically based on real-time conditions including network type, UE characteristics, and current network load. The system can adjust access policies on-the-fly, granting or restricting access based on current circumstances rather than using static pre-configured rules, thereby optimizing access efficiency.
3Measurement precision
If comprehensive UE information is collected from multiple networks, then authorization accuracy and security assessment are improved, but information processing complexity and data management burden increase
Solution Approach 1:
The system extracts only the necessary information needed for authorization decisions from the comprehensive UE data available in home networks. Rather than processing all available UE information, the system selectively obtains and processes specific parameters such as network type, UE category, and security indicators, reducing processing complexity while maintaining authorization accuracy.
Solution Approach 2:
Different levels of UE information are collected and processed based on the specific authorization scenario and network conditions. The system applies local quality by tailoring the information collection and processing depth to the specific access request context, rather than uniformly processing all UE data in all scenarios.
Data Source
AI summary
A system described herein may monitor information associated with a set of User Equipment (“UEs”) associated with a first network, and may receive an access request, for access to a first UE of the set of UEs, from a second UE associated with a second network. The system may obtain, based on the access request and from the second network, monitored information associated with the second UE. The system may identify monitored information associated with the first UE and a particular access policy that is associated with the first UE and the second UE. The system may identify, based on the particular access policy, the monitored information associated with the first UE, and the monitored information associated with the second UE, whether to grant or deny the access request. The system may output, in response to the access request, an indication of whether the access request is granted or denied.


