Proxy Failover for Client Security Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication systems, when a network element responsible for client authentication fails, the security association is lost, leading to prolonged service interruptions as clients must re-register through an alternative element, causing unacceptable downtime.

Innovation Solution

Implementing a failover functionality where data from a first proxy function's security association is sent to a serving function, which then creates an alternative security association with a second proxy function reachable with the same network address, ensuring seamless communication without client intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the client performs a new registration via an alternative network element when the original network element fails, then the client can be re-connected to the network, but the service interruption time increases significantly

Engineering Contradiction:
Improveclient connectivityVSAvoidservice interruption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the serving function store security association data from the first proxy function before failure occurs. When failure is detected, the alternative proxy function already has the necessary security association data ready to immediately establish connectivity, eliminating the need for the client to perform a new registration and significantly reducing service interruption time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The serving function acts as an intermediary that receives and stores security association data from the first proxy function, then provides this data to the alternative proxy function. This intermediary mechanism enables seamless failover without requiring client intervention or new registration, thus reducing service interruption time while maintaining connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the client initiates a new registration process after network element failure, then authentication can be re-established, but the client must wait for the entire registration procedure to complete

Engineering Contradiction:
ImproveauthenticationVSAvoidregistration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The serving function performs preliminary action by storing the complete security association data (including authentication information) before the network element fails. When failure occurs, this pre-stored data is immediately transferred to the alternative proxy function, allowing authentication to be re-established without requiring the client to undergo the full registration procedure again, thus reducing registration time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies copying by creating a copy of the security association data at the alternative proxy function. Instead of requiring the client to perform a new authentication registration, the alternative proxy function uses a copy of the existing security association data, enabling rapid re-establishment of authentication without the time-consuming full registration process.

Inventive Principle:
Principle #26Copying

3Reliability

If the network element fails during active communication, then the system can detect the failure, but the client becomes unreachable until new registration is completed

Engineering Contradiction:
Improvenetwork availabilityVSAvoidunreachability duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The serving function performs preliminary action by maintaining a copy of the security association data and preparing the alternative proxy function in advance. When failure is detected during active communication, the system can immediately switch to the alternative proxy function using the pre-prepared data, making the client reachable again without waiting for new registration to complete, thus reducing unreachability duration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The serving function serves as an intermediary that detects network element failure and facilitates the switch to the alternative proxy function. It provides the necessary security association data to the alternative proxy function, enabling continuous client reachability during the failover process without requiring the client to re-register, thus reducing the duration of unreachability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9417975B2Failover functionality for client-related security association
Publication Date: 2016.08.16 NOKIA SOLUTIONS & NETWORKS OY
  • US9417975B2 patent drawing
  • US9417975B2 patent drawing
  • US9417975B2 patent drawing

AI summary

There are provided measures for a failover functionality for a client-related security association. Such measures exemplarily comprise providing a failover functionality at a proxy function and/or facilitating provision of a failover functionality at a servicing call state control function, wherein the respective failover functionality relates to a first proxy function, the serving function is for servicing the first proxy function and a second proxy function, the first proxy function has a security association with a client, and the first proxy function and the second proxy function are reachable with the same network address.