Distributed Authentication Relay for Multi-Hop Wireless Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication network systems rely on a centralized approach that does not support wireless multi-hop communications, requiring a direct communication channel between the supplicant and the authenticator, which limits access and mobility in wireless communication networks.

Innovation Solution

A distributed system where a supplicant can authenticate indirectly through a prime authenticator and authentication relay nodes, allowing authentication requests to be relayed through intermediate nodes, enabling multi-hop access and mobility by creating states at each authentication node to manage authentication information and pairwise master keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a centralized authentication approach is used with a single IAP handling all supplicants, then authentication security is maintained through direct communication channels, but wireless multi-hop access and device mobility are limited

Engineering Contradiction:
Improvemulti-hop access capabilityVSAvoidauthentication system structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the centralized authentication function into distributed authentication capabilities across multiple IAPs. Each IAP can independently authenticate supplicants through relay authentication, where an authenticated supplicant at one IAP can authenticate other supplicants at different IAPs. This segmentation enables multi-hop access while maintaining security through distributed trust relationships.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authenticated supplicants as intermediary nodes that relay authentication requests between IAPs. These intermediary supplicants act as trusted mediators that enable indirect authentication paths, allowing supplicants to access networks through multiple hops while maintaining security through the intermediary's established credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If direct communication channels are required between supplicant and authenticator, then authentication security is simplified, but network flexibility and device mobility are reduced

Engineering Contradiction:
Improvedevice mobilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent uses authenticated supplicants as intermediaries to establish secure indirect communication paths. The intermediary supplicant relays authentication messages between the moving supplicant and IAPs, maintaining security through encrypted relay channels while enabling mobility through multiple access points.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates copies of authentication credentials and trust relationships across multiple IAPs through the relay authentication mechanism. When a supplicant is authenticated at one IAP, the authentication state is copied and validated at other IAPs, enabling the supplicant to move between networks while maintaining secure access.

Inventive Principle:
Principle #26Copying

3Area of stationary object

If all supplicants must be authenticated through a single IAP, then authentication management is simplified, but access coverage and network scalability are limited

Engineering Contradiction:
Improveauthentication coverage areaVSAvoidauthentication management
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

The patent divides the authentication management function across multiple IAPs, with each IAP managing local supplicants and relaying authentication information for remote supplicants. This segmentation extends authentication coverage to multiple network areas while distributing management complexity across the IAP infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes IAPs universal nodes that can both authenticate local supplicants directly and relay authentication requests for supplicants accessing through other IAPs. This multi-functionality allows any IAP to serve as an authentication point for any supplicant in the network, extending coverage while maintaining standardized management procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8850194B2System and methods for providing multi-hop access in a communications network
Publication Date: 2014.09.30 MOTOROLA SOLUTIONS INC
  • US8850194B2 patent drawing
  • US8850194B2 patent drawing
  • US8850194B2 patent drawing

AI summary

A system and methods for providing a supplicant access to a communications network are disclosed. An authenticator receives an authentication request at an authenticator (210) from the supplicant. A state is created based on the authentication request at the authenticator (210). The authentication request is relayed towards a prime authenticator (215) where the prime authenticator is connected to an authentication server. Finally, the authenticator (215) receives authentication information from the prime authenticator and fulfills the authentication request using the authentication information.