Hierarchical AAA Authentication for Roaming Latency Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication and authorization procedures for mobile terminals roaming between heterogeneous networks result in significant latency due to lengthy information transfers between local AAA servers and home AAA servers, hindering seamless network access, especially in networks with small coverage areas or overlapping domains.
Innovation Solution
A method and system for hierarchical authentication and authorization that detects roaming events, identifies involved network elements, and selects appropriate authentication procedures, reducing the need for frequent interactions with the home AAA server by allocating and distributing local security information within the foreign network domain, thereby optimizing network access performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication and authorization procedures are used for mobile terminals roaming between heterogeneous networks, then authentication and authorization can be performed, but significant latency occurs due to lengthy information transfers between local AAA servers and home AAA servers
Solution Approach 1:
The patent segments the authentication and authorization process into hierarchical levels. Local AAA servers are given autonomous authentication capabilities for terminals within their own domains, eliminating the need to contact home AAA servers for every authentication request. This segmentation allows local servers to handle routine authentications independently, significantly reducing roaming latency while maintaining security.
Solution Approach 2:
The patent implements preliminary action by pre-establishing trust relationships and security credentials between local AAA servers and home AAA servers before roaming occurs. Home AAA servers can pre-authenticate terminals and provide authentication credentials that local servers can use independently. This preliminary setup eliminates real-time communication delays during actual roaming authentication events.
2Productivity
If hierarchical authentication procedures are implemented to reduce roaming latency, then network access performance is optimized, but the complexity of the authentication system increases
Solution Approach 1:
The patent applies universality by designing local AAA servers with multi-functionality. These servers can both contact home AAA servers when needed and independently authenticate terminals using pre-established credentials. This universal capability allows the same server infrastructure to handle both centralized and decentralized authentication scenarios, reducing overall system complexity despite hierarchical implementation.
Solution Approach 2:
The authentication system is made dynamic by allowing local AAA servers to adaptively choose between contacting home AAA servers or performing independent authentication based on available credentials and current roaming scenarios. This dynamic behavior optimizes performance by selecting the fastest valid authentication path while maintaining system manageability through policy-based control.
3Loss of time
If local security information is distributed within the foreign network domain to minimize interactions with the home AAA server, then roaming latency is reduced, but the security requirements and management complexity increase
Solution Approach 1:
Security credentials and trust relationships are established in advance between local AAA servers and home AAA servers before roaming occurs. Home servers pre-authenticate themselves to local servers and provide cryptographic credentials that enable subsequent independent authentications. This preliminary security setup minimizes real-time information transfer while maintaining strong security, as the heavy credential exchange happens only once during initial configuration.
Data Source
AI summary
A method, system, and network elements for authentication and authorization of a mobile terminal (MT) roaming to or in a foreign network different from its home network is provided, the home network having an authentication and authorization home server (AAAH), and the foreign network having a plurality of domains each of which comprises at least one local server (AAAL1, AAAL2) for authentication, authorization and accounting, each of which local servers being connected to at least one network access server (NAS) for handling access for mobile terminals roaming to or in the foreign network, wherein an authentication and authorization of the mobile terminal is performed whenever the mobile terminal performs a roaming, wherein the authentication and authorization is performed according to a procedure pursuant to one of a plurality of hierarchy levels, whereby a combination of network elements involved in the roaming determines the hierarchy level to be used.


