Fail-open network device bypasses non-responsive subscriber storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network technologies face reliability issues when critical authentication devices become overloaded or fail, leading to exclusion of subscribers from network services despite other systems operating properly.

Innovation Solution

Implementing a fail-open function in network devices, such as serving gateways and subscriber data storage, which allows the network to continue functioning by bypassing non-responsive authentication systems and forwarding requests to other nodes, ensuring network services are maintained even if primary authentication systems fail.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication processes and authorization processes are implemented to provide network security, then network security is improved, but network reliability deteriorates because subscriber access is blocked when authentication devices fail

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidnetwork security
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a fail-open function that is pre-configured in network devices to automatically activate when authentication devices become overloaded or fail. This beforehand cushioning mechanism ensures that subscriber devices can maintain network access through alternative pathways, preventing complete network service disruption while preserving security through coordinated failover to backup authentication systems.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent introduces intermediary network devices with fail-open capabilities that act as mediators between subscriber devices and primary authentication systems. When authentication devices fail, these intermediary devices enable alternative authentication pathways, maintaining both network security and reliability by bridging the gap between compromised authentication infrastructure and subscriber access requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If critical authentication devices are used to verify subscriber devices, then network security is improved, but device complexity increases and single points of failure are created

Engineering Contradiction:
Improvenetwork robustnessVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into multiple independent network devices, each capable of performing authentication functions. This segmentation eliminates single points of failure by distributing authentication capabilities across multiple devices, allowing the network to maintain security while improving robustness through decentralized authentication architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements multi-functional network devices that can perform both primary authentication and fail-open operations. These universal devices can switch between normal authentication modes and fail-open modes depending on system conditions, reducing overall system complexity by consolidating multiple functions into single devices while maintaining network robustness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8856328B2Fail-open network techniques
Publication Date: 2014.10.07 CELLCO PARTNERSHIP INC
  • US8856328B2 patent drawing
  • US8856328B2 patent drawing
  • US8856328B2 patent drawing

AI summary

A network device may receive, from a user device, a request for network access to a network and communicate a request, to a subscriber data storage, for subscriber data, corresponding to the user device, to verify whether the user device may be granted network access. The network platform may determine, in response to communicating the request to the subscriber data storage, that the subscriber data storage is non-responsive and executing a fail-open function in response to determining that the subscriber data storage is non-responsive. The fail-open function may include processing the request for network access without subscriber data from the subscriber data storage and granting network access to the user device without verifying that the user device is permitted to access the network.