Policy-Based EAP Authentication Offload via Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current EAP authentication systems lack efficient mechanisms for policy-based extensions and decision-making processes to offload devices from cellular networks to WiFi, leading to suboptimal resource utilization and user experience.

Innovation Solution

A system and method that intercepts EAP authentication messages to determine device location and traffic conditions, using a policy thresholding server to decide whether to offload devices to WiFi, sending an EAP Failure message if offload is not permitted, thereby managing network resources and user data plans effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAP authentication is performed for all devices, then authentication security is maintained, but network resource utilization becomes inefficient

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork resource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the authentication decision-making function from the traditional EAP server and implements it at intermediate network nodes (WiFi offload decision points). This allows selective authentication where devices are redirected to WiFi based on location and policy, rather than forcing all devices through cellular EAP authentication, thereby improving network resource utilization while maintaining security through targeted authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces intermediate decision points between the device and the EAP server where authentication decisions are made based on location information and policies. These intermediaries (network nodes) evaluate whether a device should be offloaded to WiFi before completing EAP authentication, enabling efficient resource allocation without compromising the security of the authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If devices are offloaded to WiFi networks, then RAN capacity requirements are reduced, but authentication control complexity increases

Engineering Contradiction:
ImproveRAN capacity requirementsVSAvoidauthentication control complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the authentication control function into multiple components: location determination modules, policy evaluation modules, and authentication decision modules distributed at different network nodes. This segmentation allows the complex task of determining when to offload devices to WiFi to be divided into manageable functions, reducing the complexity burden on any single system while still achieving RAN capacity optimization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic authentication control where decisions to offload devices to WiFi are made in real-time based on current location information and network policies. The system adapts its authentication behavior dynamically rather than using static rules, allowing flexible response to changing network conditions while managing complexity through automated decision-making algorithms.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If real-time location monitoring is implemented, then offload decisions become more accurate, but information processing overhead increases

Engineering Contradiction:
Improveoffload decision accuracyVSAvoidinformation processing overhead
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies partial action by monitoring and processing location information selectively rather than continuously for all devices. The system determines location and enables offload decisions only when necessary (e.g., when device mobility is detected or policy requires it), rather than maintaining constant monitoring, thereby reducing information processing overhead while maintaining sufficient accuracy for effective WiFi offloading decisions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11051167B2System and method for policy-based extensible authentication protocol authentication
Publication Date: 2021.06.29 AT&T INTELLECTUAL PROPERTY I L P
  • US11051167B2 patent drawing
  • US11051167B2 patent drawing
  • US11051167B2 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, a device that includes a processing system and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations such as receiving an extensible authentication protocol (EAP) authentication message addressed to an EAP authentication server from a communication device; extracting information from the EAP authentication message; determining whether to reject a request in the EAP authentication message of the communication device based on the information extracted; and sending an EAP Failure message to the communication device after intercepting an authentication and key agreement message from the communication device based on the determining indicating that the request should be rejected. Other embodiments are disclosed.