Network Authentication Control for Load Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G and other cellular systems, natural disasters, network congestion, or device failures can lead to a large number of concurrent authentication requests, overwhelming the access and application networks, causing network overload and potential disconnections or session drops.

Innovation Solution

The solution involves selectively skipping certain authentication operations, allowing terminals to use network services after authenticating with only one of the access or application networks, rather than both, under high-load conditions, and using relay nodes to coordinate authentication across multiple nodes, reducing the load on authentication nodes and increasing network robustness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If terminals authenticate with both access network and application network, then security and reliability are improved, but network load and authentication complexity increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements selective authentication where terminals only need to authenticate with one network (access or application) rather than both, reducing authentication complexity while maintaining security through conditional logic and network coordination mechanisms

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If all authentication requests are processed normally, then authentication completeness is maintained, but network overload occurs during high-load conditions

Engineering Contradiction:
Improveauthentication completenessVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

During high-load conditions, the system selectively processes only necessary authentication requests by skipping redundant authentication operations, allowing the network to handle critical communications while reducing overall authentication load

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication system dynamically adjusts its behavior based on network load conditions, transitioning between full authentication mode and selective authentication mode to optimize network throughput while maintaining essential service availability

Inventive Principle:
Principle #15Dynamics

3Reliability

If dual authentication is required, then security is enhanced, but service availability during high-load conditions decreases

Engineering Contradiction:
ImprovesecurityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs only the necessary authentication operation (either access network or application network authentication) rather than both, maintaining security through conditional logic while improving service availability during high-load conditions

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11196731B2Network-authentication control
Publication Date: 2021.12.07 T MOBILE US INC
  • US11196731B2 patent drawing
  • US11196731B2 patent drawing
  • US11196731B2 patent drawing

AI summary

In some examples, an authentication node of a telecommunications network can receive an authentication request from a terminal, and an authentication-control message. The authentication node can skip an authentication operation with respect to the authentication request in response to the authentication-control message. In some examples, a relay node of the telecommunications network can detect an overload or service-interruption condition and determine, in response, the authentication-control message. The relay node can send the authentication-control message to the authentication node. In some examples, an authentication node can detect that its load level satisfies a predetermined criterion and, in response, skip an authentication operation and send a first message. Another authentication node can receive an indication of the first message and, in response, perform a second authentication operation.