Network Access Server Proxying Authentication Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network access systems face challenges in seamlessly providing wholesale and retail communications network access across disparate administrative domains, particularly when external authentication is required, as they often lack a network connection between AAA servers for secure and private information exchange, leading to security risks and inefficiencies.
Innovation Solution
The solution involves a network access server that partly steers its operation to identify and invoke the responsible AAA server for user authentication and authorization, even if the initial AAA server is not responsible, allowing it to select or configure a path to the correct AAA server for authentication and authorization, thereby bypassing the need for a direct network connection between AAA servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a direct network connection between AAA servers is established for authentication message exchange, then communication reliability is improved, but network security and system complexity worsen due to security risks and infrastructure requirements
Solution Approach 1:
The Network Access Server acts as an intermediary that receives authentication requests from clients and forwards them to the appropriate AAA server. Instead of requiring direct connections between AAA servers, the NAS mediates all communication, eliminating security risks associated with inter-AAA-server connections while ensuring reliable message delivery through the centralized NAS coordination
2Adaptability or versatility
If AAA servers are distributed across multiple administrative domains, then system scalability and adaptability are improved, but system complexity worsens due to the need for direct network connections between servers
Solution Approach 1:
The NAS serves as a universal intermediary that coordinates authentication across multiple administrative domains without requiring direct connections between AAA servers in different domains. The NAS receives requests, determines the appropriate AAA server, and manages the communication, thereby supporting multi-domain operations while simplifying the network infrastructure
Solution Approach 2:
The Network Access Server performs multiple functions including receiving client requests, determining the appropriate AAA server, forwarding authentication messages, and managing accounting information. This multi-functional approach eliminates the need for specialized direct connections between AAA servers, allowing distributed multi-domain deployment with reduced infrastructure complexity
3Productivity
If the Network Access Server directly communicates with the correct AAA server, then authentication efficiency is improved, but the ability to handle external authentication and proxying worsens
Solution Approach 1:
The NAS acts as an intermediary that maintains high authentication efficiency by directly receiving and processing client requests while simultaneously providing adaptability through its ability to determine and forward requests to the appropriate AAA server, including external AAA servers in other administrative domains. This mediation approach enables both fast local authentication and flexible external authentication proxying
Data Source
AI summary
The invention relates to providing network access to separate virtual private network. It relates to a method for proxying user authentication-authorization-and-accounting messages via a network access server (NAS) and at least two separated virtual private networks (VPNs), wherein a first VPN has it's own first authentication-authorization-and-accounting server (AAA server), and a second VPN has it's own second AAA server, comprising the steps of:said NAS D2 invokes (2) said first AAA server D7 for a user authentication-authorization-and-accounting and when said first AAA server D7 is not responsible for the user authentication-authorization-and-accounting,said first AAA server D7 partly steers the NAS D2 operation and identifying a configuration for a responsible second AAA server D8, if this information is available and if no information is available, forcing said NAS D2 to select or identify a configuration for the responsible second AAA server D8 andsaid NAS D2 invokes said second AAA server D8, based on the said configuration, andthis second AAA server D8 performs a real user authentication-authorization-and-accounting and a decisive steering of the NAS operation (5).Further it relates to a network access server, an authentication-authorization-and-accounting server, and computer software products for proxying user authentication-authorization-and-accounting messages via a network access server.


