Hierarchical AAA Authentication for Roaming Latency Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication and authorization procedures for mobile terminals roaming between heterogeneous networks result in significant latency due to lengthy information transfers between local AAA servers and home AAA servers, hindering seamless network access, especially in networks with small coverage areas or overlapping domains.

Innovation Solution

A method and system for hierarchical authentication and authorization that detects roaming events, identifies involved network elements, and selects appropriate authentication procedures, reducing the need for frequent interactions with the home AAA server by allocating and distributing local security information within the foreign network domain, thereby optimizing network access performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication and authorization procedures are used for mobile terminals roaming between heterogeneous networks, then authentication and authorization can be performed, but significant latency occurs due to lengthy information transfers between local AAA servers and home AAA servers

Engineering Contradiction:
Improveauthentication and authorization capabilityVSAvoidroaming latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the authentication and authorization process into hierarchical levels. Local AAA servers are given autonomous authentication capabilities for terminals within their own domains, eliminating the need to contact home AAA servers for every authentication request. This segmentation allows local servers to handle routine authentications independently, significantly reducing roaming latency while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-establishing trust relationships and security credentials between local AAA servers and home AAA servers before roaming occurs. Home AAA servers can pre-authenticate terminals and provide authentication credentials that local servers can use independently. This preliminary setup eliminates real-time communication delays during actual roaming authentication events.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If hierarchical authentication procedures are implemented to reduce roaming latency, then network access performance is optimized, but the complexity of the authentication system increases

Engineering Contradiction:
Improvenetwork access performanceVSAvoidauthentication system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing local AAA servers with multi-functionality. These servers can both contact home AAA servers when needed and independently authenticate terminals using pre-established credentials. This universal capability allows the same server infrastructure to handle both centralized and decentralized authentication scenarios, reducing overall system complexity despite hierarchical implementation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication system is made dynamic by allowing local AAA servers to adaptively choose between contacting home AAA servers or performing independent authentication based on available credentials and current roaming scenarios. This dynamic behavior optimizes performance by selecting the fastest valid authentication path while maintaining system manageability through policy-based control.

Inventive Principle:
Principle #15Dynamics

3Loss of time

If local security information is distributed within the foreign network domain to minimize interactions with the home AAA server, then roaming latency is reduced, but the security requirements and management complexity increase

Engineering Contradiction:
Improveinformation transfer timeVSAvoidsecurity management complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

Security credentials and trust relationships are established in advance between local AAA servers and home AAA servers before roaming occurs. Home servers pre-authenticate themselves to local servers and provide cryptographic credentials that enable subsequent independent authentications. This preliminary security setup minimizes real-time information transfer while maintaining strong security, as the heavy credential exchange happens only once during initial configuration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7461248B2Authentication and authorization in heterogeneous networks
Publication Date: 2008.12.02 NOKIA TECHNOLOGIES OY
  • US7461248B2 patent drawing
  • US7461248B2 patent drawing
  • US7461248B2 patent drawing

AI summary

A method, system, and network elements for authentication and authorization of a mobile terminal (MT) roaming to or in a foreign network different from its home network is provided, the home network having an authentication and authorization home server (AAAH), and the foreign network having a plurality of domains each of which comprises at least one local server (AAAL1, AAAL2) for authentication, authorization and accounting, each of which local servers being connected to at least one network access server (NAS) for handling access for mobile terminals roaming to or in the foreign network, wherein an authentication and authorization of the mobile terminal is performed whenever the mobile terminal performs a roaming, wherein the authentication and authorization is performed according to a procedure pursuant to one of a plurality of hierarchy levels, whereby a combination of network elements involved in the roaming determines the hierarchy level to be used.