Universal Authentication for Heterogeneous IP Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3G system architectures face challenges in authenticating mobile devices across various network access methods, such as CDMA2000, WLAN, and Bluetooth, due to the lack of a universal authentication process, which complicates access and mobility in multi-access scenarios.
Innovation Solution
A system and method that allow mobile devices to authenticate through different access networks by determining the network access type, creating a start message with user identity, and encapsulating it in an authentication message compatible with the identified network, enabling a single access controller to forward the message to the correct authentication server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication protocols are used for different network access technologies (CDMA2000, WLAN, Bluetooth), then each network can be authenticated independently, but the device complexity and number of authentication messages increase
Solution Approach 1:
The patent implements a universal authentication mechanism where a single EAP (Extensible Authentication Protocol) framework can handle multiple network access technologies (CDMA2000, WLAN, Bluetooth, Ethernet) through a common authentication server and message structure. The access network type is determined by the access controller, and the same EAP authentication flow is used regardless of the underlying access technology, making the authentication system multi-functional and technology-agnostic.
2Adaptability or versatility
If multiple authentication messages are sent to different authentication servers for different services, then service-specific authentication is achieved, but network traffic increases
Solution Approach 1:
The patent combines multiple authentication requests into a single EAP authentication message that is forwarded to an authentication server. The access controller consolidates authentication for multiple services (data service, signaling service, IP service) into one unified authentication exchange, reducing the number of separate authentication messages and minimizing network traffic while maintaining service-specific authentication capabilities.
3Adaptability or versatility
If the mobile device directly communicates with multiple authentication servers, then service-specific authentication is possible, but the ease of operation decreases
Solution Approach 1:
The patent introduces an access controller as an intermediary between the mobile device and the authentication server. The access controller determines the appropriate authentication server based on the access network type and forwards the EAP authentication message accordingly. This intermediary simplifies the mobile device's operation by handling the complexity of server selection and message routing, while still enabling service-specific authentication through the authentication server.
Data Source
AI summary
The invention proposes a system for authenticating and authorizing network services comprising: a mobile device being adapted to, upon receipt of an information message indicating at least one network access type, determine the network access type, to create a start message containing at least a user identity, and to encapsulate the start message in an authentication message compatible with the access network identified in the information message, and an access controller for reading the encapsulated message from the mobile and forwarding the encapsulated message to an authentication server identified in the encapsulated message. The invention also proposes a corresponding method for authenticating and authorizing network services, and an access control device, a subscriber device and a router device.


