Authentication Bootstrapping Gateway for HLR Diameter Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Communication network operators face challenges in implementing the Generic Authentication Architecture (GAA)/Generic Bootstrapping Architecture (GBA) due to the absence of a Home Subscriber System (HSS) with diameter base access, which is required by 3GPP specifications.

Innovation Solution

A method and system that allow bootstrapping without relying on a Home Subscriber System, by using a non-diameter interface to request authentication information from a home location register and security settings from a separate database, enabling authentication bootstrapping using a Mobile Application Part protocol format.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If GAA/GBA is implemented according to 3GPP specifications using HSS with diameter base access, then authentication functionality is improved, but network complexity and upgrade requirements increase

Engineering Contradiction:
Improveauthentication functionalityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the HLR and BSF. This gateway translates MAP protocol messages from the HLR into Diameter protocol messages for the BSF, enabling authentication functionality without requiring direct HSS infrastructure. The gateway acts as a protocol translator and mediator, resolving the contradiction by maintaining authentication reliability while avoiding the need for operators to upgrade to complex HSS systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication system into distinct functional components: the existing HLR remains unchanged, a new gateway device handles protocol translation, and the BSF operates with standard Diameter interface. This segmentation allows operators to adopt GAA/GBA authentication functionality without replacing entire HSS systems, reducing network complexity while maintaining authentication reliability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If HSS with diameter base access is deployed, then GAA/GBA compliance is improved, but cost and risk of database updates increase

Engineering Contradiction:
ImproveGAA/GBA complianceVSAvoidcost and risk of database updates
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The gateway device serves as an intermediary that enables GAA/GBA compliance without requiring HSS deployment. It translates MAP protocol messages from the existing HLR into Diameter format for the BSF, allowing operators to achieve GAA/GBA compliance while keeping their existing HLR infrastructure and avoiding costly database migration risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway device creates a virtual Diameter interface by translating MAP messages into Diameter protocol messages. This copying approach allows the BSF to interact with the authentication system as if a native HSS were present, achieving GAA/GBA compliance without physically deploying HSS hardware or migrating sensitive authentication databases.

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If non-diameter interface is used to access HLR, then existing HLR infrastructure can be utilized, but authentication information retrieval complexity increases

Engineering Contradiction:
Improveutilization of existing HLR infrastructureVSAvoidprotocol translation complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The gateway device acts as an intermediary that handles the complexity of protocol translation between MAP and Diameter. By centralizing this translation function in a dedicated gateway, the system can utilize existing HLR infrastructure while managing protocol complexity in a controlled manner rather than requiring complex integration at multiple points in the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2103078B1Authentication bootstrapping in communication networks
Publication Date: 2017.09.20 NOKIA TECHNOLOGIES OY
  • EP2103078B1 patent drawingFigure 1
  • EP2103078B1 patent drawingFigure 2
  • EP2103078B1 patent drawingFigure 3

AI summary

Disclosed is a method including receiving an authentication bootstrapping request related to a subscriber, requesting authentication information of said subscriber from a subscriber database, requesting security settings of said subscriber from a security setting database, receiving a response at least from one of the subscriber database and the security setting database, and proceeding with authentication bootstrapping at least partially on the basis of response(s) received. Also disclosed are related apparatuses, systems and computer programs.