Authentication Device Key Management for Communication Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, the existing EAP protocol-based authentication systems face challenges in managing multiple valid keys for a single communication participant across different authentication sessions and devices, leading to potential service disruptions and resource inefficiencies due to unclear key ownership.

Innovation Solution

An authentication device assigns a unique identifier to communication participants, enabling service servers to manage keys from different authentication sessions securely, even with non-unique identifiers, and facilitates key rollover to ensure stable communication and resource optimization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple EAP authentications are performed in parallel or in quick succession, then key material is generated for each authentication session, but the service server cannot determine which key belongs to which communication participant, leading to service disruptions and resource inefficiency

Engineering Contradiction:
ImproveAbility to perform multiple authenticationsVSAvoidService continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authentication device as an intermediary between the communication participant and the service server. This device stores the mapping between communication participant identities and authentication session identifiers, and provides this information to the service server when needed. The intermediary resolves the confusion about key ownership by translating between the participant's identity and the session-specific identifiers without requiring the service server to directly manage multiple keys

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication device implements a feedback mechanism where it monitors authentication sessions and actively provides information to service servers about which keys are valid for which participants. When a service server needs to verify a participant's identity, it queries the authentication device, which returns the appropriate session identifier and key material. This feedback loop ensures service continuity even when multiple authentications occur

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple authentication sessions are maintained for a single participant, then key material is available for each session, but service servers create additional participant sessions unnecessarily, occupying resources

Engineering Contradiction:
ImproveAuthentication session managementVSAvoidResource occupation on service server
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent extracts the functionality of managing authentication session identifiers and key mappings from the service server and places it in a dedicated authentication device. The service server only needs to store a single participant session, while the authentication device handles the complexity of multiple authentication sessions and their corresponding keys. This extraction reduces resource occupation on the service server while maintaining the ability to support multiple authentications

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If communication participants use different identifiers for different authentications, then flexibility is improved, but the service server cannot consistently identify the same participant across different sessions

Engineering Contradiction:
ImproveIdentifier flexibilityVSAvoidParticipant identity consistency
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The authentication device serves as an intermediary that maintains the mapping between different identifiers used by participants and their underlying identity. When a participant uses a different identifier for a new authentication, the authentication device stores the mapping between the new identifier, the authentication session identifier, and the participant's identity. This allows the service server to consistently identify participants across sessions through the authentication device's mapping without requiring the participant to use the same identifier

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication device creates and manages copies of participant identity information in the form of authentication session identifiers. Each authentication session generates a session identifier that is linked to the participant's identity through the authentication device's storage. This copying mechanism allows multiple identifiers to represent the same participant without losing identity consistency, as the authentication device maintains the authoritative mapping

Inventive Principle:
Principle #26Copying

Data Source

PatentEP1985086B1Method for transferring data in a communication network
Publication Date: 2016.03.16 SIEMENS AG
  • EP1985086B1 patent drawingFigure 1
  • EP1985086B1 patent drawingFigure 2~2A
  • EP1985086B1 patent drawingFigure 2B

AI summary

The invention relates to method for transferring data from an authentication device to additional communication network elements wherein a characteristic associated with a communication subscriber is transferred therewith. The additional communication network elements can allocate the captured data to the communication subscriber using the transferred characteristic.