Access Network Authentication With Time-Window Replay Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating access network devices are vulnerable to replay attacks, making it difficult to distinguish between legal and illegal access network devices, thereby compromising communication security.

Innovation Solution

A method involving a terminal device sending an authentication request and checking if the response falls within a specified time window, with additional mechanisms to handle delays or errors, ensuring the response is not a replayed message.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the terminal device uses unidirectional broadcast messages for authentication, then the authentication process is simple and fast, but the system becomes vulnerable to replay attacks and cannot reliably distinguish legal from illegal access network devices

Engineering Contradiction:
Improveauthentication speedVSAvoidauthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements periodic action by establishing a time window mechanism where the terminal device expects the authentication response within a specific time period. The access network device must respond within this predetermined time window, creating a periodic constraint that prevents replay attacks while maintaining efficient authentication flow.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies feedback by having the terminal device send not only authentication requests but also time window information back to the access network device. This feedback mechanism allows the terminal to verify whether the response received is within the expected time window, enabling detection of replay attacks while maintaining authentication simplicity.

Inventive Principle:
Principle #23Feedback

2Reliability

If the terminal device checks whether the response time falls within a time window, then replay attack resistance is improved, but the authentication process complexity increases

Engineering Contradiction:
Improvereplay attack resistanceVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the terminal device pre-establish the time window parameter before the authentication exchange. The terminal device determines the time window based on system information received beforehand, so that during the actual authentication process, it only needs to check whether the response falls within this pre-defined window, reducing real-time computational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies parameter changes by using the time window as a configurable parameter that can be adjusted based on network conditions. The terminal device obtains time window information from the access network device and uses this parameter to determine whether the response is valid, simplifying the verification process while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the terminal device implements time window checking for authentication, then communication security is enhanced, but network delays or errors may cause false rejection of legal access network devices

Engineering Contradiction:
Improvecommunication securityVSAvoidfalse rejection rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies beforehand cushioning by establishing a time window that accommodates normal network delays and processing time. The time window is designed to be sufficiently large to cover expected network conditions, preventing false rejection of legal access network devices while still being small enough to detect replay attacks. This cushioning approach balances security with tolerance for network variability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentEP3996404B1Method for authenticating access network device and related device
Publication Date: 2025.08.27 HUAWEI TECH CO LTD
  • EP3996404B1 patent drawingFigure 1
  • EP3996404B1 patent drawingFigure 2A
  • EP3996404B1 patent drawingFigure 2B

AI summary

Embodiments of this application disclose a method for authenticating an access network device and a related device, to determine whether an access network device communicating with a terminal device is a legal access network device. The method in the embodiments of this application includes: A terminal device sends an authentication request to an access network device, receives, in a first transmission time unit, a first authentication request response in response to the authentication request, and obtains first time window information in the first authentication request response. Because the first time window information may indicate a time range in which the terminal device receives the first authentication request response, when the terminal device determines that the first transmission time unit falls within a first time window indicated by the first time window information, the terminal device may determine that the access network device is a legal access network device. Therefore, this can prevent the terminal device from being connected to an illegal access network device, and can further prevent the terminal device from suffering a replay attack.