Authentication Device Network Permission Granting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wide area network instability leads to prolonged wait periods for terminals during authentication due to packet loss and delays in authentication success messages between authentication devices and servers.

Innovation Solution

The method involves granting initial network permission to terminals based on reputation data and withdrawing it upon authentication failure, allowing the authentication device to grant broader permissions upon successful authentication without waiting for confirmation from the server, thus reducing wait times and improving user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the authentication device waits for confirmation from the server before granting network permission, then authentication security is improved, but terminal wait time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidterminal wait time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication device performs preliminary actions by granting network permission in advance based on initial authentication results before receiving final confirmation from the server. This preliminary action reduces terminal wait time while maintaining security through subsequent verification steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the authentication process by allowing provisional network access based on initial authentication, then dynamically revoking or confirming permission based on final server verification. This dynamic approach balances security requirements with user experience.

Inventive Principle:
Principle #15Dynamics

2Loss of time

If the authentication device grants network permission based on initial authentication results, then terminal wait time is reduced, but network security risk increases

Engineering Contradiction:
Improveterminal wait timeVSAvoidnetwork security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the authentication device continuously monitors for server confirmation responses. Upon receiving feedback from the server, the device either confirms the provisional permission or revokes it if authentication fails, thus maintaining security while enabling fast initial access.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system prepares cushioning measures by implementing a verification mechanism that can quickly revoke permission if the initial authentication was incorrect. This beforehand cushioning protects against security risks while allowing fast initial access.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If the authentication device retransmits authentication messages due to packet loss, then authentication reliability is improved, but authentication delay increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication device performs preliminary authentication actions locally before server confirmation is required. This preliminary action ensures that even if packet loss occurs and retransmission is needed, the terminal can access the network quickly based on initial successful authentication indicators.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3654608B1Method, apparatus and device for granting network permission to terminal
Publication Date: 2023.10.11 HUAWEI TECH CO LTD
  • EP3654608B1 patent drawingFigure 1
  • EP3654608B1 patent drawingFigure 2A
  • EP3654608B1 patent drawingFigure 2B

AI summary

A method and an apparatus for granting network permission to a terminal, and a device are disclosed, to resolve a problem of a long wait period of a terminal resulting from WAN instability. The method includes: receiving, by an authentication device, a network permission request packet sent by a terminal; granting, by the authentication device, first network permission to the terminal; after granting the first network permission to the terminal, receiving, by the authentication device, a first authentication failure message sent by a server; and withdrawing, by the authentication device, the first network permission of the terminal based on the first authentication failure message. Therefore, the authentication device can grant the network permission to the terminal before receiving an authentication result sent by the server, and withdraw the network permission in time when receiving the first authentication failure message sent by the server.