Access Network Authentication With Time-Window Replay Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for authenticating access network devices are vulnerable to replay attacks, making it difficult to distinguish between legal and illegal access network devices, thereby compromising communication security.
Innovation Solution
A method involving a terminal device sending an authentication request and checking if the response falls within a specified time window, with additional mechanisms to handle delays or errors, ensuring the response is not a replayed message.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the terminal device uses unidirectional broadcast messages for authentication, then the authentication process is simple and fast, but the system becomes vulnerable to replay attacks and cannot reliably distinguish legal from illegal access network devices
Solution Approach 1:
The patent implements periodic action by establishing a time window mechanism where the terminal device expects the authentication response within a specific time period. The access network device must respond within this predetermined time window, creating a periodic constraint that prevents replay attacks while maintaining efficient authentication flow.
Solution Approach 2:
The patent applies feedback by having the terminal device send not only authentication requests but also time window information back to the access network device. This feedback mechanism allows the terminal to verify whether the response received is within the expected time window, enabling detection of replay attacks while maintaining authentication simplicity.
2Reliability
If the terminal device checks whether the response time falls within a time window, then replay attack resistance is improved, but the authentication process complexity increases
Solution Approach 1:
The patent implements preliminary action by having the terminal device pre-establish the time window parameter before the authentication exchange. The terminal device determines the time window based on system information received beforehand, so that during the actual authentication process, it only needs to check whether the response falls within this pre-defined window, reducing real-time computational complexity.
Solution Approach 2:
The patent applies parameter changes by using the time window as a configurable parameter that can be adjusted based on network conditions. The terminal device obtains time window information from the access network device and uses this parameter to determine whether the response is valid, simplifying the verification process while maintaining security.
3Reliability
If the terminal device implements time window checking for authentication, then communication security is enhanced, but network delays or errors may cause false rejection of legal access network devices
Solution Approach 1:
The patent applies beforehand cushioning by establishing a time window that accommodates normal network delays and processing time. The time window is designed to be sufficiently large to cover expected network conditions, preventing false rejection of legal access network devices while still being small enough to detect replay attacks. This cushioning approach balances security with tolerance for network variability.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Embodiments of this application disclose a method for authenticating an access network device and a related device, to determine whether an access network device communicating with a terminal device is a legal access network device. The method in the embodiments of this application includes: A terminal device sends an authentication request to an access network device, receives, in a first transmission time unit, a first authentication request response in response to the authentication request, and obtains first time window information in the first authentication request response. Because the first time window information may indicate a time range in which the terminal device receives the first authentication request response, when the terminal device determines that the first transmission time unit falls within a first time window indicated by the first time window information, the terminal device may determine that the access network device is a legal access network device. Therefore, this can prevent the terminal device from being connected to an illegal access network device, and can further prevent the terminal device from suffering a replay attack.