Proxy Failover for Client Security Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication systems, when a network element responsible for client authentication fails, the security association is lost, leading to prolonged service interruptions as clients must re-register through an alternative element, causing unacceptable downtime.
Innovation Solution
Implementing a failover functionality where data from a first proxy function's security association is sent to a serving function, which then creates an alternative security association with a second proxy function reachable with the same network address, ensuring seamless communication without client intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the client performs a new registration via an alternative network element when the original network element fails, then the client can be re-connected to the network, but the service interruption time increases significantly
Solution Approach 1:
The patent applies preliminary action by having the serving function store security association data from the first proxy function before failure occurs. When failure is detected, the alternative proxy function already has the necessary security association data ready to immediately establish connectivity, eliminating the need for the client to perform a new registration and significantly reducing service interruption time.
Solution Approach 2:
The serving function acts as an intermediary that receives and stores security association data from the first proxy function, then provides this data to the alternative proxy function. This intermediary mechanism enables seamless failover without requiring client intervention or new registration, thus reducing service interruption time while maintaining connectivity.
2Reliability
If the client initiates a new registration process after network element failure, then authentication can be re-established, but the client must wait for the entire registration procedure to complete
Solution Approach 1:
The serving function performs preliminary action by storing the complete security association data (including authentication information) before the network element fails. When failure occurs, this pre-stored data is immediately transferred to the alternative proxy function, allowing authentication to be re-established without requiring the client to undergo the full registration procedure again, thus reducing registration time.
Solution Approach 2:
The patent applies copying by creating a copy of the security association data at the alternative proxy function. Instead of requiring the client to perform a new authentication registration, the alternative proxy function uses a copy of the existing security association data, enabling rapid re-establishment of authentication without the time-consuming full registration process.
3Reliability
If the network element fails during active communication, then the system can detect the failure, but the client becomes unreachable until new registration is completed
Solution Approach 1:
The serving function performs preliminary action by maintaining a copy of the security association data and preparing the alternative proxy function in advance. When failure is detected during active communication, the system can immediately switch to the alternative proxy function using the pre-prepared data, making the client reachable again without waiting for new registration to complete, thus reducing unreachability duration.
Solution Approach 2:
The serving function serves as an intermediary that detects network element failure and facilitates the switch to the alternative proxy function. It provides the necessary security association data to the alternative proxy function, enabling continuous client reachability during the failover process without requiring the client to re-register, thus reducing the duration of unreachability.
Data Source
AI summary
There are provided measures for a failover functionality for a client-related security association. Such measures exemplarily comprise providing a failover functionality at a proxy function and/or facilitating provision of a failover functionality at a servicing call state control function, wherein the respective failover functionality relates to a first proxy function, the serving function is for servicing the first proxy function and a second proxy function, the first proxy function has a security association with a client, and the first proxy function and the second proxy function are reachable with the same network address.


