RADIUS Server Trust Cache for Roaming Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network roaming authentication methods experience significant delays due to synchronous messaging sequences, especially when the RADIUS server is geographically distant, leading to noticeable user experience issues.

Innovation Solution

Implementing a distributed secure memory cache with a time-limited trust relationship between authentication servers, allowing asynchronous authentication messaging sequences and reducing the need for synchronous coordination between authentication servers and user devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If synchronous messaging sequences are used for RADIUS authentication between networks, then authentication reliability is ensured through strict coordination, but authentication latency increases significantly especially when servers are geographically distant

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing trust relationships between RADIUS servers before authentication is needed. When a RADIUS server receives an authentication request from a roaming user, it checks for pre-stored trust relationships with the home network's RADIUS server, allowing immediate authentication without waiting for synchronous round-trip communications across geographical distances.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a distributed data store that mediates between RADIUS servers. This data store holds pre-shared trust relationships that allow servers to authenticate users without direct synchronous communication, acting as an intermediary that eliminates the need for real-time coordination between geographically distant servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict synchronous coordination is implemented between authentication servers and user devices, then authentication security is maintained through coordinated messaging, but user experience deteriorates due to noticeable delays during network roaming

Engineering Contradiction:
Improveauthentication securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by pre-establishing trust relationships in a distributed data store before users need to roam between networks. This allows authentication to proceed asynchronously without requiring users to wait for synchronous coordination, maintaining security while improving user experience during network transitions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamics by allowing authentication messaging sequences to operate asynchronously rather than strictly synchronously. The system dynamically adapts the coordination level based on pre-established trust relationships, enabling faster authentication when trust exists while maintaining security protocols, thereby improving user experience without compromising authentication security.

Inventive Principle:
Principle #15Dynamics

3Productivity

If asynchronous authentication messaging sequences are implemented, then authentication speed increases by eliminating synchronous waiting, but coordination complexity between authentication servers increases

Engineering Contradiction:
Improveauthentication speedVSAvoidcoordination complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary distributed data store to manage asynchronous authentication messaging. This data store stores pre-established trust relationships that simplify coordination between servers, allowing them to operate asynchronously without increasing complexity. The intermediary handles the coordination burden, enabling fast authentication while maintaining manageable system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3526947B1Improvements in and relating to network communication
Publication Date: 2023.05.24 GLOBAL REACH TECH INC
  • EP3526947B1 patent drawingFigure 1A~1C
  • EP3526947B1 patent drawingFigure 2
  • EP3526947B1 patent drawingFigure 3

AI summary

Providing authentication servers (e.g. a RADIUS server) combined with a distributed data store (e.g. a memory cache) for storing a time-limited trust relationship message to establish/enable a time-limited trust between the authentication servers during network roaming of a user device. This circumvents the need for the traditional method of synchronous authentication messaging sequences, permitting transmission of authentication messaging sequences in a more time- efficient asynchronous manner.