AP Handover Authentication Using LSC Timestamp Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In ultra-dense 5G networks, managing and securing small base stations is challenging due to the difficulty in authenticating user equipment (UE) with rogue or untrusted access points (APs, leading to security threats and reduced network experience from frequent authentication processes.

Innovation Solution

A device authentication method involving timestamps exchanged between a local service center (LSC), target AP, and terminal to verify the legitimacy of APs and UEs during switching events, using public-key certificates and hash values to ensure authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional two-way identity authentication method is used between core network and user equipment, then user access security can be maintained, but user equipment may be threatened by rogue small base stations and access security cannot be guaranteed

Engineering Contradiction:
Improveuser access securityVSAvoidthreat from rogue small base stations
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Local Service Center (LSC) as an intermediary authentication entity that mediates between the terminal and access points. The LSC performs centralized authentication and generates timestamps that both the terminal and target AP verify, preventing rogue APs from compromising security while maintaining reliable access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication actions by having the LSC pre-generate and distribute timestamps to both the terminal and the target AP before the actual handover occurs. This preliminary timestamp distribution ensures that when the handover happens, both parties already possess valid authentication credentials, preventing rogue AP interference.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If each user equipment and each access point perform access authentication individually, then authentication security is maintained, but authentication efficiency is adversely affected due to frequent switching between user equipment and access points

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple individual authentication processes into a single centralized authentication operation performed by the LSC. Instead of each AP and UE performing separate authentication, the LSC handles authentication for multiple UEs switching between APs simultaneously, maintaining security while dramatically improving efficiency during handovers.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The LSC serves as a universal authentication authority that handles authentication for multiple different UEs and APs with a single standardized timestamp-based mechanism. This multi-functional approach allows the same authentication protocol to serve numerous handover scenarios, improving overall system efficiency without compromising security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If frequent authentication processes are performed during user equipment movement, then access security is maintained, but user network experience is reduced

Engineering Contradiction:
Improveaccess securityVSAvoidnetwork experience time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent ensures continuity of useful action by maintaining valid timestamp credentials across handover events. Once the LSC issues timestamps to the terminal and target AP, these credentials remain valid through the handover process, eliminating the need for repeated authentication interruptions and ensuring continuous network access without degrading user experience.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent allows the authentication process to be skipped during handover by using pre-validated timestamps. Instead of performing time-consuming authentication procedures during each handover event, the system rushes through the transition using already-verified credentials, significantly reducing latency and improving network experience while maintaining security.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS12483886B2Device authentication method and apparatus
Publication Date: 2025.11.25 DATANG MOBILE COMM EQUIP CO LTD
  • US12483886B2 patent drawing
  • US12483886B2 patent drawing
  • US12483886B2 patent drawing

AI summary

A device authentication method and an apparatus are provided, to solve the problem of how to perform an authentication for the device in a UUDN. The method includes: obtaining, by a target access point (AP), a first timestamp sent by a local service center (LSC) device and a second timestamp sent by a terminal, where the second timestamp is sent by the LSC device to the terminal, and the first timestamp and the second timestamp are sent by the LSC device based on an AP switching event; when the first timestamp is consistent with the second timestamp, determining, by the target AP, that the terminal is an access terminal of the target AP.