Distributed Authentication Relay for Multi-Hop Wireless Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication network systems rely on a centralized approach that does not support wireless multi-hop communications, requiring a direct communication channel between the supplicant and the authenticator, which limits access and mobility in wireless communication networks.
Innovation Solution
A distributed system where a supplicant can authenticate indirectly through a prime authenticator and authentication relay nodes, allowing authentication requests to be relayed through intermediate nodes, enabling multi-hop access and mobility by creating states at each authentication node to manage authentication information and pairwise master keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a centralized authentication approach is used with a single IAP handling all supplicants, then authentication security is maintained through direct communication channels, but wireless multi-hop access and device mobility are limited
Solution Approach 1:
The patent segments the centralized authentication function into distributed authentication capabilities across multiple IAPs. Each IAP can independently authenticate supplicants through relay authentication, where an authenticated supplicant at one IAP can authenticate other supplicants at different IAPs. This segmentation enables multi-hop access while maintaining security through distributed trust relationships.
Solution Approach 2:
The patent introduces authenticated supplicants as intermediary nodes that relay authentication requests between IAPs. These intermediary supplicants act as trusted mediators that enable indirect authentication paths, allowing supplicants to access networks through multiple hops while maintaining security through the intermediary's established credentials.
2Adaptability or versatility
If direct communication channels are required between supplicant and authenticator, then authentication security is simplified, but network flexibility and device mobility are reduced
Solution Approach 1:
The patent uses authenticated supplicants as intermediaries to establish secure indirect communication paths. The intermediary supplicant relays authentication messages between the moving supplicant and IAPs, maintaining security through encrypted relay channels while enabling mobility through multiple access points.
Solution Approach 2:
The patent creates copies of authentication credentials and trust relationships across multiple IAPs through the relay authentication mechanism. When a supplicant is authenticated at one IAP, the authentication state is copied and validated at other IAPs, enabling the supplicant to move between networks while maintaining secure access.
3Area of stationary object
If all supplicants must be authenticated through a single IAP, then authentication management is simplified, but access coverage and network scalability are limited
Solution Approach 1:
The patent divides the authentication management function across multiple IAPs, with each IAP managing local supplicants and relaying authentication information for remote supplicants. This segmentation extends authentication coverage to multiple network areas while distributing management complexity across the IAP infrastructure.
Solution Approach 2:
The patent makes IAPs universal nodes that can both authenticate local supplicants directly and relay authentication requests for supplicants accessing through other IAPs. This multi-functionality allows any IAP to serve as an authentication point for any supplicant in the network, extending coverage while maintaining standardized management procedures.
Data Source
AI summary
A system and methods for providing a supplicant access to a communications network are disclosed. An authenticator receives an authentication request at an authenticator (210) from the supplicant. A state is created based on the authentication request at the authenticator (210). The authentication request is relayed towards a prime authenticator (215) where the prime authenticator is connected to an authentication server. Finally, the authenticator (215) receives authentication information from the prime authenticator and fulfills the authentication request using the authentication information.


