Decentralized Authentication in Wireless Ad-Hoc Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless ad-hoc communication systems, the lack of a centralized management device for terminal-authorization-certificates poses challenges in authenticating and managing access rights, as terminals are constantly moving and do not maintain a consistent communication path with a collective management device.

Innovation Solution

A wireless ad-hoc communication system where terminals independently issue terminal-authorization-certificates by transmitting beacon information to suggest certificate issuance requests, allowing for decentralized authentication and access management through the exchange of public key certificates and revocation lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized management device is used for terminal-authorization-certificate management, then authentication and access control can be effectively performed, but the system cannot adapt to wireless ad-hoc networks where terminals are constantly moving and communication paths are not consistent

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidadaptability to mobile ad-hoc environment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the centralized certificate management function into distributed segments where each terminal can independently issue certificates to other terminals. Instead of one central authority, multiple terminal authorization certificate issuing functions are segmented across the network, allowing the system to maintain authentication reliability while adapting to mobile ad-hoc environments where centralized management is impractical.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Terminals are empowered to issue their own authorization certificates to other terminals without requiring external centralized management. Each terminal performs self-service authentication by generating and distributing its own certificates, enabling the system to operate reliably in mobile ad-hoc networks where terminals constantly move and centralized management devices are inaccessible.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If terminals independently issue certificates without centralized management, then the system becomes adaptable to mobile ad-hoc environments, but authentication security and access control reliability may be compromised

Engineering Contradiction:
Improveadaptability to mobile ad-hoc environmentVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Before terminals engage in data communication, they perform preliminary authentication by exchanging terminal authorization certificates. This preliminary action ensures that even though terminals independently issue certificates, the authentication reliability is maintained because verification occurs before any actual communication takes place, preventing unauthorized access from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where terminals verify received certificates against stored revocation lists and validate certificate authenticity through cryptographic verification. This feedback loop ensures that independently-issued certificates are properly validated, maintaining authentication reliability despite the decentralized issuance process.

Inventive Principle:
Principle #23Feedback

3Ease of manufacture

If terminal authorization certificates are managed collectively by a specific device, then certificate issuance and revocation can be centrally controlled, but this approach is unsuitable for wireless ad-hoc networks where communication paths to management devices are not always maintained

Engineering Contradiction:
Improveease of certificate managementVSAvoidsuitability for ad-hoc network
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The centralized certificate management function is segmented and distributed to individual terminals. Each terminal maintains its own authorization certificate and can independently issue certificates to other terminals, eliminating the need for continuous communication with a central management device and making the system suitable for mobile ad-hoc networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each terminal is designed to perform multiple functions: it can act as both a certificate holder and a certificate issuing authority. This multi-functionality allows any terminal to independently manage authentication for itself and others, providing universal certificate management capability across the ad-hoc network without requiring dedicated management infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7797531B2Wireless ad-hoc communication system, terminal, method for suggesting issuance of attribute certificate and method for requesting issuance of attribute certificate in the terminal, and program for causing the terminal to execute the methods
Publication Date: 2010.09.14 SONY GROUP CORP
  • US7797531B2 patent drawing
  • US7797531B2 patent drawing
  • US7797531B2 patent drawing

AI summary

A wireless ad-hoc communication system in which an attribute certificate can be independently and dispersedly issued is provided. A terminal (B200) transmits a beacon (2011) for participating in a network in the wireless ad-hoc communication system. The beacon (2011) indicates whether or not the terminal (B200) has an attribute certificate. Upon receiving the beacon (2011), a terminal (A100) checks the beacon. If it is determined that the terminal (B200) does not have an attribute certificate, the terminal (A100) transmits an attribute-certificate issuance suggestion message (1032) for suggesting an attribute-certificate issuing request to the terminal (B200). When the terminal (B200) transmits an attribute-certificate issuance request message (2041) in response to this message, the terminal (A100) transmits an attribute-certificate issuance message (1052) to the terminal (B200).