Virtual Network Session Admission via Segmented Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In conventional mobile networks, admitting user sessions to virtual networks (VNs) is challenging due to the decoupling of Radio Access Networks (RAN) from Core Networks, requiring new methods for authentication and authorization that are not exclusively performed within the Core Network domain.
Innovation Solution
A method for admitting user sessions in virtual networks involves receiving an attach request, performing authentication challenges with the User Equipment and an Authentication Function associated with the virtual network, and admitting the equipment to a session upon successful authentication, using a mobility management function within the core network domain, and utilizing an Authentication and Authorization function to confirm user device authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If authentication and authorization are performed exclusively within the Core Network domain, then security and control are maintained, but the ability to support decoupled RAN and virtual network architectures is limited
Solution Approach 1:
The patent segments the authentication and authorization functions into separate network domains. The Access Domain handles initial attach requests and basic authentication, while the Virtual Network Domain handles authorization and service-specific authentication. This segmentation allows the system to support decoupled RAN and virtual network architectures without requiring all authentication functions to reside in the Core Network domain, thereby improving adaptability while managing complexity through functional separation.
2Adaptability or versatility
If a single entity owns and administers all network resources, then network control and management are simplified, but the ability to provide virtual network services to multiple operators is limited
Solution Approach 1:
The patent implements a universal authentication and authorization framework that can serve multiple virtual network operators through a single infrastructure. The Mobility Management Entity in the Access Domain can handle attach requests from multiple operators, while the Virtual Network Domain provides centralized authorization services for different virtual networks. This multi-functionality allows a single entity to provide virtual network services to multiple operators while maintaining relatively simple control and management through standardized interfaces and procedures.
3Adaptability or versatility
If the RAN is associated with a single Core Network, then network architecture is simplified, but the ability to access multiple Core Network slices is prevented
Solution Approach 1:
The patent introduces an intermediary Virtual Network Domain that mediates between the Access Domain and multiple Core Network slices. When a UE attaches to the RAN, the Mobility Management Entity in the Access Domain communicates with the Virtual Network Domain, which then determines the appropriate Core Network slice or virtual network for the user. This intermediary approach enables the RAN to access multiple Core Network slices without directly increasing the complexity of the RAN-Core Network interface, as the Virtual Network Domain absorbs the complexity of multi-slice management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An aspect of the disclosure provides a method of admitting a session from a user device subscribed to a service with a virtual network operator. The method includes receiving a service request from said user device at an Access Point and selecting a network function Authentication and Authorization (AA) function (AAF) to confirm the user device is authorized for the requested service, and transmitting the request to the selected network function AAA function. The AAAF which processes the request may reside with the virtual network operator (VNO). However, the VNO may share its AAA database with other network entities (for example, Telecom Connectivity Service Providers (TCSPs) or InPs), and allow those entities to perform the AAA functions.