Wireless Network Authentication Signaling Reduction via Mobility Domains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In densely populated wireless networks, mobile users generate excessive authentication signaling, leading to backhaul congestion and processing overload, as existing systems perform unnecessary authentication even for users not engaging in data traffic.
Innovation Solution
The system groups access points into zones or clusters, using a master access point or proxy authentication to reduce authentication signaling by maintaining a virtual access point, allowing devices to move within the group without re-authentication, and broadcasting group identifiers to minimize air interface traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication signaling is performed for every access point transition, then authentication security is maintained, but network congestion and processing overload occur
Solution Approach 1:
The network is segmented into mobility domains, where each domain is managed by a domain authentication server. Users are authenticated once within a domain and can move between access points in the same domain without re-authentication, reducing signaling overhead while maintaining security boundaries between domains
Solution Approach 2:
Authentication is performed in advance when a user first joins a mobility domain. The authentication result is cached and valid for subsequent movements within the domain, eliminating the need for repeated authentication signaling during handovers
2Reliability
If authentication requests are sent frequently by mobile users, then continuous authentication is ensured, but backhaul congestion and processing loads increase
Solution Approach 1:
Authentication is performed preliminarily when the user enters a mobility domain, and the authentication context is preserved. Subsequent movements within the domain reuse this pre-established authentication, avoiding repeated processing loads
Solution Approach 2:
A mobility domain authentication server acts as an intermediary that manages authentication contexts for multiple access points within a domain. It handles authentication requests centrally and provides authentication results to access points, reducing individual processing loads at each access point
3Adaptability or versatility
If users move between access points, then network mobility is enabled, but authentication signaling overhead increases
Solution Approach 1:
The network is divided into mobility domains, each with its own authentication server. Users can move freely within a domain without re-authentication, as the domain server manages their authentication context. This segmentation reduces signaling overhead compared to traditional per-access-point authentication
Solution Approach 2:
Multiple access points within a mobility domain are merged into a single authentication context managed by the domain server. The domain server aggregates authentication management for all access points in the domain, reducing redundant signaling that would occur with independent authentication at each access point
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for reducing authentication signaling in a wireless network includes identifying a plurality of access points in a network belonging to a group. An access request message is received from a first access point associated with a device being in range of the first access point. A determination is made whether the device has been authenticated within the group. A proxy accept message is sent to the to the first access point in response to the device being authenticated with the group without communicating with an authentication server for authentication of the device. A master access point may be used in performing the reduction of authentication signaling in the wireless network.