Unified Authentication Server Decoupling HSS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network architectures face challenges in managing network authentication and subscription management across multiple access types, particularly in mobile communication networks, due to the complexity of managing multiple authentication and policy functions, which leads to the need for multiple nodes and lack of mechanisms to correlate user or device sessions across different access types.
Innovation Solution
The solution involves decoupling authentication and subscription management functions from a 3GPP Home Subscriber Server (HSS) and merging them with an Authentication, Authorization, and Accounting (AAA) function and a Network Policy Function (NPF), splitting the S6a interface into S6a-Auth and S6a-SM interfaces, and using a unified user or device profile to map access-specific identities to a common identity, allowing for unified authentication and policy management across wired, wireless, and private cellular access technologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple authentication and policy functions are used to manage different access types, then authentication coverage is improved, but device complexity increases
Solution Approach 1:
The patent combines multiple authentication functions (3GPP HSS, non-3GPP AAA) and policy functions into a single unified authentication server. This consolidation maintains the ability to handle multiple access types (cellular, Wi-Fi, wired) while reducing the number of separate network nodes required, thereby decreasing overall device complexity while preserving authentication coverage.
Solution Approach 2:
The unified authentication server is designed to perform multiple authentication functions simultaneously - it can authenticate 3GPP cellular access, non-3GPP Wi-Fi access, and wired access all through a single node. This multi-functional approach eliminates the need for separate specialized authentication servers for each access type, resolving the contradiction between versatility and complexity.
2Adaptability or versatility
If separate authentication functions are used for different access types, then authentication specificity is improved, but ease of operation deteriorates
Solution Approach 1:
The unified authentication server provides a single point of management for all authentication operations across different access types. Operators can configure and manage cellular, Wi-Fi, and wired authentication through one interface rather than coordinating multiple separate systems, significantly improving ease of operation while maintaining access-specific authentication capabilities.
Solution Approach 2:
The patent introduces a unified authentication server as an intermediary that handles all authentication requests from different access types. This central mediator simplifies operation by providing a single point of control and configuration, eliminating the need for operators to manage multiple separate authentication systems while preserving the specificity needed for different access types.
3Adaptability or versatility
If multiple nodes are deployed for different access types, then authentication capability is improved, but device complexity increases
Solution Approach 1:
The patent merges the functionality of multiple authentication nodes (HSS for cellular, AAA for Wi-Fi) into a single unified authentication server. This consolidation maintains the comprehensive authentication capability across all access types while reducing the number of physical or virtual network nodes required, thereby decreasing device complexity while preserving authentication capability.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Techniques are described to provide for authentication and subscription management that are decoupled from a Home Subscriber Server (HSS). In one example, a method includes providing a device profile at an authentication function, wherein the device profile comprises identification information for a device for a plurality of access types including a first identifier for the device associated with a cellular access and a second identifier for the device associated with a wireless local area network access; obtaining an access request message associated with the device for the cellular access, wherein the access request message comprises the first identifier and an authentication attribute; generating authentication information for authenticating the device for the cellular access based, at least in part, on the authentication attribute; and generating, for transmission, an access accept message for the cellular access, wherein the access accept message comprises the first identifier, the second identifier, and the authentication information.