Universal Authentication for Heterogeneous IP Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3G system architectures face challenges in authenticating mobile devices across various network access methods, such as CDMA2000, WLAN, and Bluetooth, due to the lack of a universal authentication process, which complicates access and mobility in multi-access scenarios.

Innovation Solution

A system and method that allow mobile devices to authenticate through different access networks by determining the network access type, creating a start message with user identity, and encapsulating it in an authentication message compatible with the identified network, enabling a single access controller to forward the message to the correct authentication server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication protocols are used for different network access technologies (CDMA2000, WLAN, Bluetooth), then each network can be authenticated independently, but the device complexity and number of authentication messages increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism where a single EAP (Extensible Authentication Protocol) framework can handle multiple network access technologies (CDMA2000, WLAN, Bluetooth, Ethernet) through a common authentication server and message structure. The access network type is determined by the access controller, and the same EAP authentication flow is used regardless of the underlying access technology, making the authentication system multi-functional and technology-agnostic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple authentication messages are sent to different authentication servers for different services, then service-specific authentication is achieved, but network traffic increases

Engineering Contradiction:
Improveservice access capabilityVSAvoidnetwork traffic
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent combines multiple authentication requests into a single EAP authentication message that is forwarded to an authentication server. The access controller consolidates authentication for multiple services (data service, signaling service, IP service) into one unified authentication exchange, reducing the number of separate authentication messages and minimizing network traffic while maintaining service-specific authentication capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If the mobile device directly communicates with multiple authentication servers, then service-specific authentication is possible, but the ease of operation decreases

Engineering Contradiction:
Improveservice provisioning capabilityVSAvoidauthentication operation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an access controller as an intermediary between the mobile device and the authentication server. The access controller determines the appropriate authentication server based on the access network type and forwards the EAP authentication message accordingly. This intermediary simplifies the mobile device's operation by handling the complexity of server selection and message routing, while still enabling service-specific authentication through the authentication server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8341700B2Authentication in heterogeneous IP networks
Publication Date: 2012.12.25 NOKIA TECHNOLOGIES OY
  • US8341700B2 patent drawing
  • US8341700B2 patent drawing
  • US8341700B2 patent drawing

AI summary

The invention proposes a system for authenticating and authorizing network services comprising: a mobile device being adapted to, upon receipt of an information message indicating at least one network access type, determine the network access type, to create a start message containing at least a user identity, and to encapsulate the start message in an authentication message compatible with the access network identified in the information message, and an access controller for reading the encapsulated message from the mobile and forwarding the encapsulated message to an authentication server identified in the encapsulated message. The invention also proposes a corresponding method for authenticating and authorizing network services, and an access control device, a subscriber device and a router device.