RADIUS Server Trust Cache for Roaming Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional network roaming authentication methods experience significant delays due to synchronous messaging sequences, especially when the RADIUS server is geographically distant, leading to noticeable user experience issues.
Innovation Solution
Implementing a distributed secure memory cache with a time-limited trust relationship between authentication servers, allowing asynchronous authentication messaging sequences and reducing the need for synchronous coordination between authentication servers and user devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If synchronous messaging sequences are used for RADIUS authentication between networks, then authentication reliability is ensured through strict coordination, but authentication latency increases significantly especially when servers are geographically distant
Solution Approach 1:
The patent applies preliminary action by pre-establishing trust relationships between RADIUS servers before authentication is needed. When a RADIUS server receives an authentication request from a roaming user, it checks for pre-stored trust relationships with the home network's RADIUS server, allowing immediate authentication without waiting for synchronous round-trip communications across geographical distances.
Solution Approach 2:
The patent uses an intermediary approach by introducing a distributed data store that mediates between RADIUS servers. This data store holds pre-shared trust relationships that allow servers to authenticate users without direct synchronous communication, acting as an intermediary that eliminates the need for real-time coordination between geographically distant servers.
2Reliability
If strict synchronous coordination is implemented between authentication servers and user devices, then authentication security is maintained through coordinated messaging, but user experience deteriorates due to noticeable delays during network roaming
Solution Approach 1:
The system performs preliminary actions by pre-establishing trust relationships in a distributed data store before users need to roam between networks. This allows authentication to proceed asynchronously without requiring users to wait for synchronous coordination, maintaining security while improving user experience during network transitions.
Solution Approach 2:
The patent introduces dynamics by allowing authentication messaging sequences to operate asynchronously rather than strictly synchronously. The system dynamically adapts the coordination level based on pre-established trust relationships, enabling faster authentication when trust exists while maintaining security protocols, thereby improving user experience without compromising authentication security.
3Productivity
If asynchronous authentication messaging sequences are implemented, then authentication speed increases by eliminating synchronous waiting, but coordination complexity between authentication servers increases
Solution Approach 1:
The patent uses an intermediary distributed data store to manage asynchronous authentication messaging. This data store stores pre-established trust relationships that simplify coordination between servers, allowing them to operate asynchronously without increasing complexity. The intermediary handles the coordination burden, enabling fast authentication while maintaining manageable system complexity.
Data Source
Figure 1A~1C
Figure 2
Figure 3
AI summary
Providing authentication servers (e.g. a RADIUS server) combined with a distributed data store (e.g. a memory cache) for storing a time-limited trust relationship message to establish/enable a time-limited trust between the authentication servers during network roaming of a user device. This circumvents the need for the traditional method of synchronous authentication messaging sequences, permitting transmission of authentication messaging sequences in a more time- efficient asynchronous manner.