Authentication Server Intermediary for Secure Wireless Roaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in securely transferring data between wireless devices and multiple networks, leading to inefficiencies in roaming, increased power consumption, and infrastructure modifications, particularly when switching between IEEE 802.11 Wi-Fi and IEEE 802.16 WiMAX networks.
Innovation Solution
A method for secure data transfer is implemented using a two-channel protocol, where the authentication server acts as an intermediary between the wireless device and the information server, employing EAP for the first channel and security protocols like IPSec or SSL for the second channel, enabling secure data exchange and efficient roaming without requiring additional infrastructure changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing technologies are used for data transfer between wireless devices and multiple networks, then roaming functionality is provided, but security risks increase and power consumption increases
Solution Approach 1:
The patent applies preliminary action by establishing secure authentication and data transfer protocols before the wireless device actually roams between networks. The authentication server pre-authenticates the device and establishes secure channels in advance, so that when roaming occurs, the device can switch networks without repeated authentication handshakes, thereby reducing both security risks and power consumption during the roaming process.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the wireless device and multiple networks. This intermediary centralizes the authentication and data management functions, providing a single point of security control that reduces the security burden on individual networks and enables more efficient power management during roaming operations.
2Adaptability or versatility
If existing technologies are used for data transfer between wireless devices and multiple networks, then roaming functionality is provided, but infrastructure modifications are required
Solution Approach 1:
The patent applies universality by designing the authentication server to handle multiple functions: authentication, authorization, account management, and secure data transfer. This multi-functional approach allows a single infrastructure component to support roaming across different network types (Wi-Fi, WiMAX, etc.) without requiring separate specialized infrastructure for each network or function, thereby reducing overall infrastructure complexity while maintaining high adaptability.
Solution Approach 2:
The authentication server acts as a universal intermediary that mediates between the wireless device and various network types. By centralizing the complex authentication and data management logic in this intermediary, the patent enables roaming capability across diverse networks without requiring each network to be modified or to implement complex proprietary solutions.
3Reliability
If data is transferred securely using authentication servers and multiple channels, then security is improved, but device complexity increases
Solution Approach 1:
The patent applies the extraction principle by separating the complex authentication and security management functions from the wireless device itself and placing them in the external authentication server. The device only needs to implement basic authentication client functionality, while the server handles the complex multi-channel secure data transfer, cryptographic operations, and protocol management, thereby reducing device complexity while maintaining high security.
Solution Approach 2:
The authentication server as an intermediary absorbs the protocol complexity of multi-channel secure communication. The server manages the EAP channel with the device and the IPSec/SSL channels with networks, handling the complex key management, encryption, and authentication protocols centrally, which simplifies the implementation burden on the wireless device while ensuring robust security.
Data Source
AI summary
Disclosed is a method for secure transfer of data for enabling roaming of the wireless device between a plurality of wireless networks. The wireless device data from an authentication server via a first channel. The authentication server sends the request for the data to an information server using a second channel. The information server generates the data bases on parameters of the wireless device and provides the data to the wireless device through the authentication server. The secure transfer of data to the wireless device enables roaming of the wireless device in a plurality of wireless networks.


