Virtual Network Session Admission via Segmented Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In conventional mobile networks, admitting user sessions to virtual networks (VNs) is challenging due to the decoupling of Radio Access Networks (RAN) from Core Networks, requiring new methods for authentication and authorization that are not exclusively performed within the Core Network domain.

Innovation Solution

A method for admitting user sessions in virtual networks involves receiving an attach request, performing authentication challenges with the User Equipment and an Authentication Function associated with the virtual network, and admitting the equipment to a session upon successful authentication, using a mobility management function within the core network domain, and utilizing an Authentication and Authorization function to confirm user device authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If authentication and authorization are performed exclusively within the Core Network domain, then security and control are maintained, but the ability to support decoupled RAN and virtual network architectures is limited

Engineering Contradiction:
Improvesupport for decoupled RAN and virtual network architecturesVSAvoidauthentication and authorization architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication and authorization functions into separate network domains. The Access Domain handles initial attach requests and basic authentication, while the Virtual Network Domain handles authorization and service-specific authentication. This segmentation allows the system to support decoupled RAN and virtual network architectures without requiring all authentication functions to reside in the Core Network domain, thereby improving adaptability while managing complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a single entity owns and administers all network resources, then network control and management are simplified, but the ability to provide virtual network services to multiple operators is limited

Engineering Contradiction:
Improvevirtual network service provision to multiple operatorsVSAvoidnetwork control and management simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements a universal authentication and authorization framework that can serve multiple virtual network operators through a single infrastructure. The Mobility Management Entity in the Access Domain can handle attach requests from multiple operators, while the Virtual Network Domain provides centralized authorization services for different virtual networks. This multi-functionality allows a single entity to provide virtual network services to multiple operators while maintaining relatively simple control and management through standardized interfaces and procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the RAN is associated with a single Core Network, then network architecture is simplified, but the ability to access multiple Core Network slices is prevented

Engineering Contradiction:
Improveaccess to multiple Core Network slicesVSAvoidnetwork architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary Virtual Network Domain that mediates between the Access Domain and multiple Core Network slices. When a UE attaches to the RAN, the Mobility Management Entity in the Access Domain communicates with the Virtual Network Domain, which then determines the appropriate Core Network slice or virtual network for the user. This intermediary approach enables the RAN to access multiple Core Network slices without directly increasing the complexity of the RAN-Core Network interface, as the Virtual Network Domain absorbs the complexity of multi-slice management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3295650B1Admission of a session to a virtual network service
Publication Date: 2021.04.07 HUAWEI TECH CO LTD
  • EP3295650B1 patent drawingFigure 1
  • EP3295650B1 patent drawingFigure 2
  • EP3295650B1 patent drawingFigure 3

AI summary

An aspect of the disclosure provides a method of admitting a session from a user device subscribed to a service with a virtual network operator. The method includes receiving a service request from said user device at an Access Point and selecting a network function Authentication and Authorization (AA) function (AAF) to confirm the user device is authorized for the requested service, and transmitting the request to the selected network function AAA function. The AAAF which processes the request may reside with the virtual network operator (VNO). However, the VNO may share its AAA database with other network entities (for example, Telecom Connectivity Service Providers (TCSPs) or InPs), and allow those entities to perform the AAA functions.