Network Access Server Proxying Authentication Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access systems face challenges in seamlessly providing wholesale and retail communications network access across disparate administrative domains, particularly when external authentication is required, as they often lack a network connection between AAA servers for secure and private information exchange, leading to security risks and inefficiencies.

Innovation Solution

The solution involves a network access server that partly steers its operation to identify and invoke the responsible AAA server for user authentication and authorization, even if the initial AAA server is not responsible, allowing it to select or configure a path to the correct AAA server for authentication and authorization, thereby bypassing the need for a direct network connection between AAA servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a direct network connection between AAA servers is established for authentication message exchange, then communication reliability is improved, but network security and system complexity worsen due to security risks and infrastructure requirements

Engineering Contradiction:
Improveauthentication message deliveryVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The Network Access Server acts as an intermediary that receives authentication requests from clients and forwards them to the appropriate AAA server. Instead of requiring direct connections between AAA servers, the NAS mediates all communication, eliminating security risks associated with inter-AAA-server connections while ensuring reliable message delivery through the centralized NAS coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If AAA servers are distributed across multiple administrative domains, then system scalability and adaptability are improved, but system complexity worsens due to the need for direct network connections between servers

Engineering Contradiction:
Improvemulti-domain supportVSAvoidnetwork infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The NAS serves as a universal intermediary that coordinates authentication across multiple administrative domains without requiring direct connections between AAA servers in different domains. The NAS receives requests, determines the appropriate AAA server, and manages the communication, thereby supporting multi-domain operations while simplifying the network infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Network Access Server performs multiple functions including receiving client requests, determining the appropriate AAA server, forwarding authentication messages, and managing accounting information. This multi-functional approach eliminates the need for specialized direct connections between AAA servers, allowing distributed multi-domain deployment with reduced infrastructure complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If the Network Access Server directly communicates with the correct AAA server, then authentication efficiency is improved, but the ability to handle external authentication and proxying worsens

Engineering Contradiction:
Improveauthentication speedVSAvoidexternal authentication support
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The NAS acts as an intermediary that maintains high authentication efficiency by directly receiving and processing client requests while simultaneously providing adaptability through its ability to determine and forward requests to the appropriate AAA server, including external AAA servers in other administrative domains. This mediation approach enables both fast local authentication and flexible external authentication proxying

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7624429B2Method, a network access server, an authentication-authorization-and-accounting server, and a computer software product for proxying user authentication-authorization-and-accounting messages via a network access server
Publication Date: 2009.11.24 ALCATEL
  • US7624429B2 patent drawing
  • US7624429B2 patent drawing
  • US7624429B2 patent drawing

AI summary

The invention relates to providing network access to separate virtual private network. It relates to a method for proxying user authentication-authorization-and-accounting messages via a network access server (NAS) and at least two separated virtual private networks (VPNs), wherein a first VPN has it's own first authentication-authorization-and-accounting server (AAA server), and a second VPN has it's own second AAA server, comprising the steps of:said NAS D2 invokes (2) said first AAA server D7 for a user authentication-authorization-and-accounting and when said first AAA server D7 is not responsible for the user authentication-authorization-and-accounting,said first AAA server D7 partly steers the NAS D2 operation and identifying a configuration for a responsible second AAA server D8, if this information is available and if no information is available, forcing said NAS D2 to select or identify a configuration for the responsible second AAA server D8 andsaid NAS D2 invokes said second AAA server D8, based on the said configuration, andthis second AAA server D8 performs a real user authentication-authorization-and-accounting and a decisive steering of the NAS operation (5).Further it relates to a network access server, an authentication-authorization-and-accounting server, and computer software products for proxying user authentication-authorization-and-accounting messages via a network access server.