Fast Re-authentication Secure Access After Deregistration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods do not enable secure access using the fast re-authentication procedure after a terminal deregisters from a network following a full authentication procedure.

Innovation Solution

A secure access method and system that allows a terminal to perform secure access using a fast re-authentication procedure by determining if fast re-authentication is allowed, sending a registration type identifier to a home subscriber server, and storing the authentication server address, enabling secure access even after deregistration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal performs full authentication procedure and then deregisters from the network, then the terminal can access the network initially with full security verification, but the terminal cannot perform secure access using fast re-authentication procedure in subsequent accesses

Engineering Contradiction:
Improvesecure access capabilityVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The home subscriber server performs preliminary action by storing the authentication server address in the user profile during the initial full authentication procedure, before the terminal deregisters. This pre-stored information enables the terminal to perform fast re-authentication in subsequent accesses without needing to undergo full authentication again, thus resolving the contradiction between maintaining security and improving access efficiency.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If the terminal uses fast re-authentication procedure, then the access efficiency is improved, but the secure access cannot be maintained after terminal deregistration from the network

Engineering Contradiction:
Improveaccess efficiencyVSAvoidsecure access capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanism where the home subscriber server receives notification when a terminal deregisters from the network. Based on this feedback, the server determines whether to clear the authentication server address from the user profile. This feedback loop ensures that fast re-authentication is enabled only when appropriate (when the terminal is still registered or should maintain fast access capability), thus maintaining both security and efficiency.

Inventive Principle:
Principle #23Feedback

3Productivity

If the home subscriber server stores the authentication server address in the user profile, then fast re-authentication is enabled for subsequent accesses, but the system complexity increases

Engineering Contradiction:
Improvere-authentication efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The home subscriber server performs multiple functions: it acts as both the authentication server during initial full authentication and as the storage location for the authentication server address in the user profile. By making the home subscriber server multi-functional, the patent avoids introducing additional dedicated storage components, thus enabling fast re-authentication capability while minimizing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11323440B2Secure access method, device, and system
Publication Date: 2022.05.03 HUAWEI TECH CO LTD
  • US11323440B2 patent drawing
  • US11323440B2 patent drawing
  • US11323440B2 patent drawing

AI summary

A secure access method performed by an authentication server includes receiving a first message from a non-3GPP access device. The method also includes performing fast re-authentication with the terminal when determining that fast re-authentication is allowed. The method further includes sending a second message to a home subscriber server. The second message carries a registration type identifier, an identifier of the terminal, and an address of the authentication server. The registration type identifier is used to indicate that current secure access of the terminal is secure access using a fast re-authentication procedure. The method additionally includes receiving a registration success indication from the home subscriber server. The method also includes sending an access success indication to the terminal based on the registration success indication.