AP Handover Authentication Using LSC Timestamp Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In ultra-dense 5G networks, managing and securing small base stations is challenging due to the difficulty in authenticating user equipment (UE) with rogue or untrusted access points (APs, leading to security threats and reduced network experience from frequent authentication processes.
Innovation Solution
A device authentication method involving timestamps exchanged between a local service center (LSC), target AP, and terminal to verify the legitimacy of APs and UEs during switching events, using public-key certificates and hash values to ensure authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional two-way identity authentication method is used between core network and user equipment, then user access security can be maintained, but user equipment may be threatened by rogue small base stations and access security cannot be guaranteed
Solution Approach 1:
The patent introduces a Local Service Center (LSC) as an intermediary authentication entity that mediates between the terminal and access points. The LSC performs centralized authentication and generates timestamps that both the terminal and target AP verify, preventing rogue APs from compromising security while maintaining reliable access control.
Solution Approach 2:
The patent implements preliminary authentication actions by having the LSC pre-generate and distribute timestamps to both the terminal and the target AP before the actual handover occurs. This preliminary timestamp distribution ensures that when the handover happens, both parties already possess valid authentication credentials, preventing rogue AP interference.
2Reliability
If each user equipment and each access point perform access authentication individually, then authentication security is maintained, but authentication efficiency is adversely affected due to frequent switching between user equipment and access points
Solution Approach 1:
The patent merges multiple individual authentication processes into a single centralized authentication operation performed by the LSC. Instead of each AP and UE performing separate authentication, the LSC handles authentication for multiple UEs switching between APs simultaneously, maintaining security while dramatically improving efficiency during handovers.
Solution Approach 2:
The LSC serves as a universal authentication authority that handles authentication for multiple different UEs and APs with a single standardized timestamp-based mechanism. This multi-functional approach allows the same authentication protocol to serve numerous handover scenarios, improving overall system efficiency without compromising security.
3Reliability
If frequent authentication processes are performed during user equipment movement, then access security is maintained, but user network experience is reduced
Solution Approach 1:
The patent ensures continuity of useful action by maintaining valid timestamp credentials across handover events. Once the LSC issues timestamps to the terminal and target AP, these credentials remain valid through the handover process, eliminating the need for repeated authentication interruptions and ensuring continuous network access without degrading user experience.
Solution Approach 2:
The patent allows the authentication process to be skipped during handover by using pre-validated timestamps. Instead of performing time-consuming authentication procedures during each handover event, the system rushes through the transition using already-verified credentials, significantly reducing latency and improving network experience while maintaining security.
Data Source
AI summary
A device authentication method and an apparatus are provided, to solve the problem of how to perform an authentication for the device in a UUDN. The method includes: obtaining, by a target access point (AP), a first timestamp sent by a local service center (LSC) device and a second timestamp sent by a terminal, where the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are sent by the LSC device based on an AP switching event; when the first timestamp is consistent with the second timestamp, determining, by the target AP, that the terminal is an access terminal of the target AP.


