Policy-Based EAP Authentication Offload via Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current EAP authentication systems lack efficient mechanisms for policy-based extensions and decision-making processes to offload devices from cellular networks to WiFi, leading to suboptimal resource utilization and user experience.
Innovation Solution
A system and method that intercepts EAP authentication messages to determine device location and traffic conditions, using a policy thresholding server to decide whether to offload devices to WiFi, sending an EAP Failure message if offload is not permitted, thereby managing network resources and user data plans effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP authentication is performed for all devices, then authentication security is maintained, but network resource utilization becomes inefficient
Solution Approach 1:
The patent extracts the authentication decision-making function from the traditional EAP server and implements it at intermediate network nodes (WiFi offload decision points). This allows selective authentication where devices are redirected to WiFi based on location and policy, rather than forcing all devices through cellular EAP authentication, thereby improving network resource utilization while maintaining security through targeted authentication.
Solution Approach 2:
The patent introduces intermediate decision points between the device and the EAP server where authentication decisions are made based on location information and policies. These intermediaries (network nodes) evaluate whether a device should be offloaded to WiFi before completing EAP authentication, enabling efficient resource allocation without compromising the security of the authentication process.
2Quantity of substance
If devices are offloaded to WiFi networks, then RAN capacity requirements are reduced, but authentication control complexity increases
Solution Approach 1:
The patent segments the authentication control function into multiple components: location determination modules, policy evaluation modules, and authentication decision modules distributed at different network nodes. This segmentation allows the complex task of determining when to offload devices to WiFi to be divided into manageable functions, reducing the complexity burden on any single system while still achieving RAN capacity optimization.
Solution Approach 2:
The patent implements dynamic authentication control where decisions to offload devices to WiFi are made in real-time based on current location information and network policies. The system adapts its authentication behavior dynamically rather than using static rules, allowing flexible response to changing network conditions while managing complexity through automated decision-making algorithms.
3Measurement precision
If real-time location monitoring is implemented, then offload decisions become more accurate, but information processing overhead increases
Solution Approach 1:
The patent applies partial action by monitoring and processing location information selectively rather than continuously for all devices. The system determines location and enables offload decisions only when necessary (e.g., when device mobility is detected or policy requires it), rather than maintaining constant monitoring, thereby reducing information processing overhead while maintaining sufficient accuracy for effective WiFi offloading decisions.
Data Source
AI summary
Aspects of the subject disclosure may include, for example, a device that includes a processing system and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations such as receiving an extensible authentication protocol (EAP) authentication message addressed to an EAP authentication server from a communication device; extracting information from the EAP authentication message; determining whether to reject a request in the EAP authentication message of the communication device based on the information extracted; and sending an EAP Failure message to the communication device after intercepting an authentication and key agreement message from the communication device based on the determining indicating that the request should be rejected. Other embodiments are disclosed.


