Dual Stack Authorization via RADIUS VSA Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication systems face challenges in authorizing dual stack operation for mobile devices, specifically in determining whether a mobile station is authorized for both IPv4 and IPv6 access, and in indicating unauthorized access to the appropriate IP version during simultaneous IPv4 and IPv6 requests.
Innovation Solution
The method involves using the IP-Version-Authorized RADIUS VSA in the RADIUS Access-Accept message to indicate authorization for IPv4 and IPv6, and employing local policies within the Packet Data Interworking Function (PDIF) to manage dual stack operations by establishing separate IPsec tunnels and notifying the mobile station of authorized or unauthorized access based on AAA server determinations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the PDIF allows simultaneous IPv4 and IPv6 access requests from a mobile station, then dual stack operation capability is improved, but authorization control and security management become more complex
Solution Approach 1:
The patent segments the authorization process by introducing separate authorization checks for IPv4 and IPv6 stacks. The H-AAA server divides the authorization decision into distinct components (IPv4 authorization and IPv6 authorization) that are independently evaluated and communicated to the PDIF through separate RADIUS attributes, simplifying the overall control complexity while enabling dual stack operation.
Solution Approach 2:
The patent adds a new dimension to the authorization framework by introducing IP version-specific authorization attributes (IPv4-Authorized and IPv6-Authorized flags) in the RADIUS protocol. This dimensional extension allows the system to handle multiple IP versions simultaneously without increasing operational complexity, as each IP version is managed independently through dedicated authorization parameters.
2Reliability
If the PDIF implements detailed authorization checking for each IP version, then security is improved, but processing time and computational resources increase
Solution Approach 1:
The patent applies preliminary action by performing complete authorization checks for both IPv4 and IPv6 stacks during the initial access request phase. The H-AAA server pre-determines which IP versions are authorized and communicates this information to the PDIF before any data transmission occurs. This eliminates the need for repeated authorization checks during subsequent communications, reducing processing time while maintaining security.
3Loss of information
If the system provides clear authorization indication to the mobile station, then user awareness and control are improved, but message overhead and protocol complexity increase
Solution Approach 1:
The patent extracts authorization indication information from the complex RADIUS authorization process and presents it to the mobile station in a simplified format through the IKEv2 protocol. The PDIF extracts the essential authorization status (which IP versions are authorized) and communicates this clearly to the mobile station, separating the detailed authorization logic from the user-facing interface and reducing perceived protocol complexity.
Data Source
AI summary
A method of allowing interworking authorization of dual stack operation is provided. The method allows for simultaneous operation in both IPv4 and IPv6 if a terminal is authorized and authenticated to use both versions. The method utilizes the following steps: requesting authentication from an authorization entity in a wireless communication system; and receiving an authentication message from the authorization entity if the authentication is successful, wherein the authentication message contains an authorization to use at least one internet protocol version to establish at least one secure tunnel for communication.


