Shared AAA Server for Single SIM Multi-Radio Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication systems face challenges in enabling simultaneous use of multiple wireless networks by a single SIM multi-radio device without the need for repeated authentication, authorization, and accounting processes across different wireless communication standards.

Innovation Solution

A method and system for multiple network shared access security architecture that allows a single SIM multi-radio device to establish simultaneous communication sessions across different wireless networks by sharing authentication, authorization, and accounting (AAA) information through a session control server, enabling seamless handoffs and access to multiple networks based on AAA vouchers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single SIM multi-radio device connects to multiple wireless networks independently, then each network can be accessed securely through separate authentication, but the authentication, authorization, and accounting processes must be repeated for each network, increasing complexity and time consumption

Engineering Contradiction:
Improvesecurity authenticationVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication, authorization, and accounting functions across multiple wireless networks by introducing a shared AAA server that handles authentication for both WLAN and WWAN networks. This consolidation allows the device to be authenticated once across multiple networks rather than requiring separate authentication processes for each network, thereby reducing complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The AAA server is designed with universal functionality to handle authentication requests from multiple different wireless networks (WLAN, WWAN, and other radio access networks). This multi-functional approach allows a single authentication infrastructure to serve multiple network types, eliminating the need for network-specific authentication systems and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a single SIM multi-radio device performs separate authentication for each wireless network, then each network connection is securely validated, but the time required for authentication and session establishment increases significantly

Engineering Contradiction:
Improvenetwork access securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication by establishing the user's identity and authorization status through the shared AAA server before actual network access is required. The authentication credentials are validated in advance, and session information is cached or pre-configured, allowing for faster network access without compromising security validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By combining the authentication processes for WLAN and WWAN networks into a single shared AAA server, the system eliminates redundant authentication steps. The device undergoes one authentication process that is recognized across multiple networks, significantly reducing the total time required for authentication while maintaining security standards.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple wireless networks implement independent authentication systems, then each network maintains full control over security policies, but the overall system efficiency decreases due to repeated authentication and accounting processes

Engineering Contradiction:
Improvenetwork independenceVSAvoidnetwork access efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The shared AAA server acts as an intermediary between multiple wireless networks and the authentication infrastructure. It mediates authentication requests from different networks while maintaining a unified security policy framework. This intermediary approach allows networks to maintain their independence and specific security requirements while benefiting from centralized authentication management that improves overall efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The AAA server implements universal authentication functionality that can handle requests from various network types (WLAN, WWAN, and other radio access networks) through a common interface and security framework. This multi-functional design enables the system to maintain network independence and adaptability while achieving improved productivity through streamlined authentication processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If a device establishes separate authentication sessions for each network, then network-specific security requirements are met, but the device and network infrastructure complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidsession management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication sessions into a single unified session managed by the shared AAA server. Instead of maintaining separate authentication states for WLAN and WWAN networks, the device establishes one authentication session that is recognized across all connected networks. This consolidation significantly reduces session management complexity while ensuring security compliance through the unified AAA infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The AAA server provides universal session management capability that handles authentication, authorization, and accounting for multiple network types through a single session framework. This multi-functional approach allows the device to maintain one session state rather than multiple separate sessions, reducing complexity while still meeting network-specific security requirements through the server's ability to enforce appropriate policies for each network type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9301146B2Multiple network, shared access security architecture supporting simultaneous use of single SIM multi-radio device and/or phone
Publication Date: 2016.03.29 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US9301146B2 patent drawing
  • US9301146B2 patent drawing
  • US9301146B2 patent drawing

AI summary

A method and system is presented for a mobile wireless communication device that may communicate information to a first network device for enabling authentication, authorization and/or management of accounting for the mobile wireless device for use within a first network that utilizes a first wireless communication standard. A communication session may be established with a second network that utilizes a second wireless standard based on data sent to the second network related to the first authentication, authorization and/or accounting management. The wireless mobile device is operable to establish simultaneous communication sessions with the first network and the second network without communicating authentication, authorization and/or accounting information to the second network. The first and/or second network may comprise and/or share a session control server. The mobile wireless device may receive, store and/or modify additional information associated with the authentication, authorization and/or accounting management.