Access Point Local Authentication for Network Reliability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication systems fail to determine network connectibility of devices during interruptions in communication with the authentication server, leading to incomplete network access control and service disruptions.

Innovation Solution

A communication system where devices can authenticate using both first-type and second-type authentication information, with the access point device capable of performing authentication locally when connected to the authentication server, ensuring continuous network access even during server interruptions by using temporary keys or tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed only through the authentication server device, then centralized authentication management is achieved, but network access control fails during communication interruptions with the server

Engineering Contradiction:
Improvenetwork access control reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into two parts: the authentication server device for centralized management and the access point device for local authentication operations. This segmentation allows the access point to independently perform authentication when the server is unavailable, improving reliability without requiring complete system redundancy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access point device acts as an intermediary between devices seeking network access and the authentication server. It can mediate authentication requests locally using stored authentication information, bridging the gap when direct server communication is interrupted.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the access point device performs local authentication operations, then network access control continues during server interruptions, but authentication information management becomes more complex

Engineering Contradiction:
Improvenetwork access control continuityVSAvoidauthentication processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The access point device performs preliminary authentication operations using authentication information obtained in advance from the authentication server. By preparing authentication credentials beforehand, the system enables continuous network access control during server interruptions without requiring complex real-time synchronization mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authentication information is stored in the access point device, then local authentication is enabled, but security risks increase

Engineering Contradiction:
Improvelocal authentication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The access point device stores and uses authentication information locally for local authentication operations, while the authentication server maintains the master authentication database. This local quality approach enables the access point to function independently when needed, while the centralized server maintains security and can update authentication information as required.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11962583B2Authentication system using access point device and authentication server to handle a device's network access authentication request
Publication Date: 2024.04.16 KK TOSHIBA
  • US11962583B2 patent drawing
  • US11962583B2 patent drawing
  • US11962583B2 patent drawing

AI summary

According to an embodiment, a device sends, to an access point device, a network access authentication request issued with respect to a first network. An authentication server device includes a first device-authentication processing unit that, in response to the network access authentication request, performs an authentication operation based on first-type authentication information. The access point device includes a transfer processing unit and a second device-authentication processing unit. When second-type authentication information is not included in the network access authentication request, the transfer processing unit transfers the network access authentication request to the authentication server device. When the second-type authentication information is included in the network access authentication request and when an authentication operation in the access point device is enabled, the second device-authentication processing unit performs an authentication operation based on the second-type authentication information.