Trusted Gateway WiFi Terminal PS Domain Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

WiFi terminals face overload and high costs due to the need to establish specific tunnels and undergo double authentication when accessing packet data PS service domains through WLAN, complicating operations and increasing load.

Innovation Solution

A trusted gateway communicates with WiFi terminals and the PS service domain, receiving accounting or DHCP requests to establish PDP or PDN connections, eliminating the need for specific tunnels and double authentication by using attribute information from AAA servers to facilitate access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a specific tunnel is established between the WiFi terminal and the packet data gateway, then the terminal can access the PS service domain, but the terminal load and cost increase

Engineering Contradiction:
Improveaccess capabilityVSAvoidterminal complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted gateway as an intermediary between the WiFi terminal and the packet data gateway. The trusted gateway establishes the tunnel connection on behalf of the terminal, while the terminal only needs to connect to the trusted gateway through standard WiFi protocols. This mediator approach allows the terminal to access the PS service domain without directly establishing complex tunnels, thereby reducing terminal complexity while maintaining access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If double authentication is performed (wireless access network authentication and packet data gateway authentication), then security is improved, but the operation complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the authentication processes by having the trusted gateway perform both the wireless access network authentication and the packet data gateway authentication in sequence. The terminal first authenticates with the trusted gateway for wireless access, then the trusted gateway automatically performs the second authentication with the packet data gateway using obtained authentication information. This combining approach maintains dual-layer security while presenting a simplified single-step authentication experience to the terminal user.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If the WiFi terminal supports the scheme of establishing tunnel with the packet data gateway, then direct access is enabled, but the terminal load increases

Engineering Contradiction:
Improveaccess efficiencyVSAvoidterminal energy consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The trusted gateway acts as an intermediary that handles the energy-intensive tunnel establishment and maintenance operations. Instead of the terminal directly managing complex tunnel protocols and authentication sequences, the terminal simply communicates with the trusted gateway using standard WiFi protocols. The trusted gateway then manages the tunnel connection to the packet data gateway, thereby maintaining access efficiency while significantly reducing the computational and energy burden on the terminal.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If specific tunnel establishment protocol is implemented in the terminal, then direct PS domain access is achieved, but the cost of the terminal increases

Engineering Contradiction:
Improveaccess capabilityVSAvoidterminal cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The trusted gateway serves multiple functions: it acts as a WiFi access point for terminal connection, performs wireless network authentication, establishes tunnel connections to the packet data gateway, and manages authentication sequences. By consolidating these diverse functions into a single multi-functional gateway device, the terminal itself requires only basic WiFi client functionality, eliminating the need for expensive specialized hardware or software components for tunnel management, thereby reducing terminal manufacturing cost while maintaining full PS domain access capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2816863B1Method and trusted gateway for WIFI terminal to access packet data PS service domain
Publication Date: 2019.05.22 HUAWEI TECH CO LTD
  • EP2816863B1 patent drawingFigure 1~2
  • EP2816863B1 patent drawingFigure 3~4
  • EP2816863B1 patent drawingFigure 5~6

AI summary

The embodiments of the present invention provide a method and a trusted gateway for a WiFi terminal to access a PS service domain, which can lighten the load of the WiFi terminal and reduce the complexity of operation and the cost of the WiFi terminal. The method comprises: receiving an accounting request message sent by an authentication, authorization and accounting AAA server or a dynamic host configuration protocol DHCP request message sent by the WiFi terminal; establishing, by a trusted gateway, a first packet data protocol PDP context connection or a first packet data network PDN connection with the PS service domain according to attribute information of the WiFi terminal after receiving the accounting request message or the DHCP request message, so that the WiFi terminal accesses the PS service domain via the wireless local area network, the trusted gateway, and the established first PDP context connection or the first PDN connection; wherein, the attribute information of the WiFi terminal is obtained from the AAA server for the trusted gateway to establish the first PDP context connection or the first PDN connection with the PS service domain for the WiFi terminal to access the PS service domain.