Telecommunications Access Gateway for Secure Third-Party Service Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing telecommunications service provider architectures lack a secure and flexible mechanism for third-party access to underlying functionalities, hindering the development of new revenue channels and efficient service delivery.

Innovation Solution

A third-party access gateway and profiling database are introduced to provide secure and controlled access, authenticating and authorizing third-party requests through interfaces for various services, and a data model that supports independent authorization criteria for diverse service requesters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party access is enabled to underlying functionality, then new revenue channels and service delivery efficiency are improved, but security risks and unauthorized access increase

Engineering Contradiction:
Improvethird-party access capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

An access gateway is introduced as an intermediary component between third-party applications and the telecommunications service provider's core network. The gateway authenticates third-party requests using certificates, authorizes access based on predefined policies, and proxies all communications through its own infrastructure. This mediator architecture enables secure third-party access while maintaining security control, resolving the contradiction between enabling new revenue channels and preventing unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a database data model is designed to support multiple service requester types, then authorization flexibility is improved, but system complexity increases

Engineering Contradiction:
Improveauthorization flexibilityVSAvoiddata model complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The database data model is segmented into distinct tables and schemas organized by service requester type (e.g., individual subscriber tables, corporate subscriber tables, application-level authorization tables). Each segment handles specific authorization criteria for its target audience, allowing flexible multi-type support while maintaining manageable complexity through modular organization. The segmentation enables independent authorization policies for different requester types without requiring a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7925880B2Authentication and authorization architecture for an access gateway
Publication Date: 2011.04.12 ACCENTURE GLOBAL SERVICES LTD
  • US7925880B2 patent drawing
  • US7925880B2 patent drawing
  • US7925880B2 patent drawing

AI summary

A telecommunications architecture exposes telecommunications services to third parties through a secure access gateway. The third parties may be other telecommunications service providers who employ the services to support their own products and services. The access gateway provides a secure, standardized, and controlled access platform for the exposed services, and addresses the technical problems associated with such access. In addition to providing technical solutions for efficient and secure access to exposed services, the architecture also provides an additional revenue channel for existing telecommunication service providers.