Shared AAA Server for Single SIM Multi-Radio Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional communication systems face challenges in enabling simultaneous use of multiple wireless networks by a single SIM multi-radio device without the need for repeated authentication, authorization, and accounting processes across different wireless communication standards.
Innovation Solution
A method and system for multiple network shared access security architecture that allows a single SIM multi-radio device to establish simultaneous communication sessions across different wireless networks by sharing authentication, authorization, and accounting (AAA) information through a session control server, enabling seamless handoffs and access to multiple networks based on AAA vouchers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single SIM multi-radio device connects to multiple wireless networks independently, then each network can be accessed securely through separate authentication, but the authentication, authorization, and accounting processes must be repeated for each network, increasing complexity and time consumption
Solution Approach 1:
The patent merges the authentication, authorization, and accounting functions across multiple wireless networks by introducing a shared AAA server that handles authentication for both WLAN and WWAN networks. This consolidation allows the device to be authenticated once across multiple networks rather than requiring separate authentication processes for each network, thereby reducing complexity while maintaining security.
Solution Approach 2:
The AAA server is designed with universal functionality to handle authentication requests from multiple different wireless networks (WLAN, WWAN, and other radio access networks). This multi-functional approach allows a single authentication infrastructure to serve multiple network types, eliminating the need for network-specific authentication systems and reducing overall system complexity.
2Reliability
If a single SIM multi-radio device performs separate authentication for each wireless network, then each network connection is securely validated, but the time required for authentication and session establishment increases significantly
Solution Approach 1:
The system performs preliminary authentication by establishing the user's identity and authorization status through the shared AAA server before actual network access is required. The authentication credentials are validated in advance, and session information is cached or pre-configured, allowing for faster network access without compromising security validation.
Solution Approach 2:
By combining the authentication processes for WLAN and WWAN networks into a single shared AAA server, the system eliminates redundant authentication steps. The device undergoes one authentication process that is recognized across multiple networks, significantly reducing the total time required for authentication while maintaining security standards.
3Adaptability or versatility
If multiple wireless networks implement independent authentication systems, then each network maintains full control over security policies, but the overall system efficiency decreases due to repeated authentication and accounting processes
Solution Approach 1:
The shared AAA server acts as an intermediary between multiple wireless networks and the authentication infrastructure. It mediates authentication requests from different networks while maintaining a unified security policy framework. This intermediary approach allows networks to maintain their independence and specific security requirements while benefiting from centralized authentication management that improves overall efficiency.
Solution Approach 2:
The AAA server implements universal authentication functionality that can handle requests from various network types (WLAN, WWAN, and other radio access networks) through a common interface and security framework. This multi-functional design enables the system to maintain network independence and adaptability while achieving improved productivity through streamlined authentication processes.
4Reliability
If a device establishes separate authentication sessions for each network, then network-specific security requirements are met, but the device and network infrastructure complexity increases
Solution Approach 1:
The patent merges multiple authentication sessions into a single unified session managed by the shared AAA server. Instead of maintaining separate authentication states for WLAN and WWAN networks, the device establishes one authentication session that is recognized across all connected networks. This consolidation significantly reduces session management complexity while ensuring security compliance through the unified AAA infrastructure.
Solution Approach 2:
The AAA server provides universal session management capability that handles authentication, authorization, and accounting for multiple network types through a single session framework. This multi-functional approach allows the device to maintain one session state rather than multiple separate sessions, reducing complexity while still meeting network-specific security requirements through the server's ability to enforce appropriate policies for each network type.
Data Source
AI summary
A method and system is presented for a mobile wireless communication device that may communicate information to a first network device for enabling authentication, authorization and/or management of accounting for the mobile wireless device for use within a first network that utilizes a first wireless communication standard. A communication session may be established with a second network that utilizes a second wireless standard based on data sent to the second network related to the first authentication, authorization and/or accounting management. The wireless mobile device is operable to establish simultaneous communication sessions with the first network and the second network without communicating authentication, authorization and/or accounting information to the second network. The first and/or second network may comprise and/or share a session control server. The mobile wireless device may receive, store and/or modify additional information associated with the authentication, authorization and/or accounting management.


