Fallback Identifier for Authentication in Communication Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users in transport networks, such as GSM mobile networks, face challenges accessing communication services via fallback procedures due to authentication failures when disconnected from the central network, as local user databases typically contain limited information, leading to unsatisfactory location-dependent authentication success.

Innovation Solution

A method and system that allows users to access fallback communication services by sending an authentication request to an identity management server, allocating a unique fallback identifier upon rejection, and using this identifier to obtain a fallback user profile, multimedia group profiles, and encryption keys from respective servers, enabling access to fallback communication services regardless of location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user attempts to access communication services via fallback procedure in transport networks, then the user can maintain communication capability when disconnected from central network, but authentication fails because local user databases contain limited information

Engineering Contradiction:
Improveauthentication success rateVSAvoidlocation independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a fallback identifier as an intermediary element that mediates between the user and the authentication system. When nominal authentication fails, the fallback identifier serves as a substitute key that grants access to fallback communication services, bypassing the need for complete user database information at the local relay

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a simplified copy of authentication credentials in the form of a fallback identifier. This identifier contains sufficient information to authenticate users for fallback services without requiring the complete user profile data that would normally be stored in the central user database

Inventive Principle:
Principle #26Copying

2Ease of operation

If the authentication server uses a local user database for fallback procedures, then the system can operate independently from the central network, but the database generally only contains information relating to a very small number of users

Engineering Contradiction:
Improvefallback service accessibilityVSAvoiduser information coverage
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent extracts the essential authentication function from the complete user database context. Instead of requiring the entire user profile to be stored locally, only the critical fallback identifier is extracted and stored at the relay, enabling authentication with minimal local data storage

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the authentication parameter from complete user profile verification to fallback identifier verification. This parameter change allows the local database to contain only minimal information (the fallback identifier) while still enabling authentication for fallback services

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3562188B1A configuration process and a system for accessing fallback communication services
Publication Date: 2021.10.13 AIRBUS DS SLC
  • EP3562188B1 patent drawingFigure 1
  • EP3562188B1 patent drawingFigure 2
  • EP3562188B1 patent drawingFigure 3

AI summary

One aspect of the invention relates to a configuration method for user access to fallback communication services, comprising the following steps: - an application client sends an authentication request to an identity management server; - in case of rejection: • the identity management server allocates a fallback identifier and sends the fallback identifier to the application client; • the application client sends a fallback user profile request to a configuration management server; • the application client sends a fallback multimedia group profile request to a multimedia group management server; • the application client sends a fallback multimedia group encryption key request and private communication encryption key request to an encryption key management server;• Once the application client has received the fallback user profile, the fallback media group profile(s), the fallback media group encryption key(s), and the private communications encryption key(s), the user can access fallback communication services.