Realm Rewriting for Enterprise Authentication in Shared Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile networking environments, managing service discovery for wireless networking architectures is challenging due to variations in network services across different providers, particularly when private enterprises within shared systems need to be identified for authentication, as conventional realms do not distinguish between enterprises sharing the same MCC and MNC codes.
Innovation Solution
The technique involves rewriting the realm of an identifier associated with a user device to identify the correct authentication server by querying a database with re-write rules based on the device's identity type and network identifying portion, allowing for the generation of a re-written realm that is publicly resolvable and specific to the enterprise or operator, thereby enabling accurate authentication across shared systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional realms using MCC and MNC codes are used for authentication, then authentication can be performed in shared systems, but private enterprises within shared systems cannot be distinguished and identified
Solution Approach 1:
The patent segments the authentication realm into multiple hierarchical components: the conventional MCC/MNC portion for shared system identification, and a newly introduced enterprise-specific portion (such as enterprise ID or private network identifier) for distinguishing individual enterprises. This segmentation allows both shared system authentication and enterprise-specific identification to coexist within the same authentication framework.
Solution Approach 2:
The patent adds an additional dimension to the traditional two-dimensional realm structure (MCC/MNC) by incorporating a third dimension representing enterprise identity. This transforms the realm from a flat structure into a hierarchical multi-dimensional structure, enabling simultaneous encoding of shared system information and private enterprise information without conflict.
2Adaptability or versatility
If service discovery is managed in complex wireless networking architectures with multiple providers, then comprehensive service coverage is achieved, but service discovery becomes increasingly challenging and inefficient
Solution Approach 1:
The patent introduces an intermediary authentication server that acts as a mediator between user devices and multiple network providers. This intermediary consolidates service discovery functionality, receiving authentication requests from devices, determining the appropriate visited access network, and routing requests to the correct service providers. This eliminates the need for devices to directly manage complex multi-provider service discovery, significantly improving efficiency.
Solution Approach 2:
The patent merges service discovery, authentication, and network selection functions into a unified authentication server. By combining these previously separate functions into a single centralized entity, the system simplifies the overall service discovery process while maintaining comprehensive multi-provider support, as the merged server can handle all aspects of service access through a single interface.
Data Source
AI summary
A method is provided that includes obtaining an access request for a device to access a visited access network, the access request including an authentication identifier for the device including an identity for the device and a realm comprising a network identifying portion; determining a re-write rule for the realm by querying a database based on an identity type of the device and the network identifying portion of the realm, the database including a plurality of re-write rules for a plurality of networks and a plurality of identity types; re-writing the realm based on the re-write rule using the identity for the device to generate a re-written realm; obtaining, based on the re-written realm, an address for an authentication server of an identity provider associated with the device; and performing an authentication with the authentication server using the authentication identifier to authenticate the device for the visited access network.


