GTP Intermediary Device for Wireless Roaming Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless roaming systems lack effective mechanisms to detect and prevent unauthorized or malicious communication sessions due to the absence of provisions in the GPRS tunneling protocol for identifying anomalous packets, which can lead to network abuse and interference.

Innovation Solution

An intermediate device maintains an authentication cache to verify the validity of communication signals by comparing them to stored authentication and configuration records, allowing only authenticated sessions to establish communication connections and dropping anomalous packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the GPRS tunneling protocol is used to enable wireless roaming communication, then communication connectivity between visited network and home network is established, but the protocol lacks provisions for detecting anomalous packets which leads to network abuse and interference

Engineering Contradiction:
Improvecommunication connectivityVSAvoidpacket authenticity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediate device positioned between the visited network and home network that acts as a mediator to authenticate GTP packets. This intermediary device maintains authentication records and verifies packet authenticity, thereby resolving the contradiction by adding a security layer without disrupting the existing GTP-based communication connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication verification mechanisms are added to detect anomalous packets, then network security and integrity are improved, but the complexity of the communication system increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication functionality is isolated in a separate intermediate device rather than being integrated into the core GTP protocol or existing network elements. This modular approach improves network security while minimizing the complexity increase in the overall system, as the authentication mechanism can be added without modifying existing protocol stacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the intermediate device maintains authentication cache to verify communication signals, then unauthorized access is restricted and network abuse is prevented, but the processing time and overhead increase

Engineering Contradiction:
Improveaccess controlVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The intermediate device performs authentication verification in parallel with packet forwarding operations, and maintains a cache of authentication records to avoid repeated verification of the same packets. This preliminary action approach reduces authentication processing time and minimizes the impact on communication throughput.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9826401B2Authenticated communication session for wireless roaming
Publication Date: 2017.11.21 VERIZON PATENT & LICENSING INC
  • US9826401B2 patent drawing
  • US9826401B2 patent drawing
  • US9826401B2 patent drawing

AI summary

A device forwards a set of packets between a first network device, associated with a first network, and a second network device, associated with a second network. The set of packets may be associated with permitting access, by a set of mobile devices connected to the first network, to the second network. The device may generate and store configuration information, identifying the set of mobile devices, based on the set of packets. The device may receive, from a third network device, a request associated with establishing a communication session between the third network device and a fourth network device associated with the second network, may determine, based on the configuration information, whether a particular mobile device, associated with the request, is permitted to establish the communication session, and may selectively create the communication session based on determining that the particular mobile device is permitted to establish the communication session.