RADIUS Authentication Server Service Provisioning Status Reporting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network access control systems, particularly those using the RADIUS protocol, face challenges in identifying and addressing service provisioning issues due to a lack of status reporting from network access servers to authentication servers, leading to discrepancies in authorized and provisioned services, which can result in frustrated user experiences and difficulties for service providers in managing network access.

Innovation Solution

Implementing a mechanism where the authentication server requests and receives status reports from the network access server regarding the provisioning of services, allowing for corrective actions such as revoking authorization, logging issues, or alerting relevant devices when services are not provisioned, using a result query and reporting protocol within the RADIUS framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the authentication server uses traditional RADIUS protocol for service authorization, then authentication and authorization functions are implemented, but the server cannot obtain status information about whether services are actually provisioned to endpoint devices

Engineering Contradiction:
Improveservice provisioning status informationVSAvoidprotocol complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the authentication server sends result query messages to the network access server to obtain status information about service provisioning. The network access server responds with result response messages containing the actual provisioning status, enabling the authentication server to verify whether authorized services are properly provisioned to endpoint devices.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent extends the existing RADIUS protocol framework to serve multiple functions: traditional authentication, authorization, and now also status reporting and verification. By utilizing existing RADIUS message types and extending them with new result query and result response attributes, the system achieves multi-functionality without requiring a completely new protocol architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If the network access server fails to provision services for users, then user access to paid services is blocked, but the service provider cannot readily identify which services were not provisioned or why

Engineering Contradiction:
Improveservice provisioning managementVSAvoidservice provisioning status and error information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The authentication server actively queries the network access server for service provisioning status using result query messages. The network access server provides detailed feedback through result response messages, including information about which services are provisioned, which are not provisioned, and the reasons for provisioning failures. This enables service providers to easily identify and resolve provisioning issues.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The authentication server acts as an intermediary between the network access server and the service provider's management systems. It collects provisioning status information from the network access server and can relay this information to accounting servers or network provisioning devices, facilitating easier service provisioning management and troubleshooting.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the authentication server requests service provisioning status from the network access server, then service provisioning problems can be identified, but additional protocol messages and processing are required

Engineering Contradiction:
Improveservice provisioning accuracyVSAvoidprotocol implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing RADIUS protocol framework, which is already widely deployed and understood in the industry. By extending existing RADIUS message types (Access-Accept, Change-Of-Authorization) with new result query and result response attributes, the system achieves reliable service provisioning verification while minimizing implementation complexity. The familiar RADIUS message structure and processing logic reduce the learning curve and deployment barriers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication server performs service provisioning verification as part of the initial authentication and authorization process. By sending result query messages immediately after authorizing services, the system proactively identifies provisioning issues before users attempt to access services, ensuring higher reliability while integrating seamlessly into the existing authentication flow.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10805298B2Result reporting for authentication, authorization and accounting protocols
Publication Date: 2020.10.13 JUNIPER NETWORKS INC
  • US10805298B2 patent drawing
  • US10805298B2 patent drawing
  • US10805298B2 patent drawing

AI summary

In general, techniques are described for provided result reporting via authentication, authorization and accounting (AAA) protocols. An authorization server comprising a control unit may be configured to perform the techniques. The control unit may authorize a network access server to allow an endpoint device to access one or more services in accordance with a network access protocol. The control unit may also request, in accordance with the network access protocol, a result from the network access server as to whether the one or more authorized services are presently provided for use by the endpoint device.