RADIUS Server Bulk CoA Data Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The inefficiency in provisioning multiple services through the RADIUS protocol due to fragmentation of service configuration data, which requires iterative processing and waiting for subsequent messages, leading to complex and time-consuming provisioning processes.

Innovation Solution

The RADIUS server sends multiple RADIUS messages containing all CoA data at once, allowing the network access server to provision services only after receiving all data, eliminating the need for iterative processing and reducing wait times.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the server fragments service configuration data into multiple RADIUS messages to comply with protocol limits, then the data can be transmitted within protocol constraints, but the router must iteratively process each portion individually, increasing provisioning time and process complexity

Engineering Contradiction:
Improveprotocol complianceVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies segmentation by dividing the service configuration data into multiple RADIUS messages that comply with protocol limits, but introduces a novel approach where the router accumulates these segmented messages and performs a single unified provisioning process after receiving all segments, rather than processing each segment individually as in traditional approaches

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The router performs preliminary accumulation of all RADIUS messages containing service configuration data before executing the provisioning process. This preliminary action allows the router to have all necessary configuration data available before starting service provisioning, eliminating the need for iterative processing and confirmation between each message segment

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the router processes each portion of CoA data individually before receiving the next message, then protocol compliance is maintained, but the provisioning process becomes iterative and time-consuming

Engineering Contradiction:
Improveprotocol complianceVSAvoidprovisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables continuous accumulation of RADIUS messages at the router without interrupting the data reception flow. The useful action of provisioning is delayed until all message segments are received, allowing continuous message reception followed by a single unified provisioning action, thereby maintaining protocol compliance while improving provisioning efficiency

Inventive Principle:
Principle #20Continuity of useful action

3Quantity of substance

If multiple RADIUS messages are sent with portions of CoA data, then complete service configuration can be delivered, but the router must wait for subsequent messages before completing provisioning

Engineering Contradiction:
Improveconfiguration data volumeVSAvoidwaiting time
Core Design Contradiction:
Quantity of substanceVSLoss of time

Solution Approach 1:

The router performs preliminary accumulation of all RADIUS messages containing service configuration data before executing the provisioning process. This preliminary action allows the router to have all necessary configuration data available before starting service provisioning, eliminating the need for iterative processing and confirmation between each message segment

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11558382B2Bulk delivery of change of authorization data via AAA protocols
Publication Date: 2023.01.17 JUNIPER NETWORKS INC
  • US11558382B2 patent drawing
  • US11558382B2 patent drawing
  • US11558382B2 patent drawing

AI summary

In general, techniques are described for supporting bulk delivery of change of authorization data in authentication, authorization, and accounting (AAA) protocols, where delivery is performed as a change of authorization after a subscriber has successfully authenticated and initially authorized. In one example, the techniques are directed to a method including determining, by a RADIUS server for a service provider network, change of authorization data for services to which the subscriber of the service provider network has subscribed. The method further includes generating, by the RADIUS server, RADIUS messages that form a transaction between the RADIUS server and a network access server acting as a RADIUS client. The RADIUS messages provide all of the change of authorization data to the network access server prior to the network access server provisioning the services. The method further includes outputting, by the RADIUS server, the RADIUS messages to the network access server.