Authentication Apparatus with Connection Configuration Checker
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network access authentication methods fail to consider the connection configuration of authentication clients, leading to unauthorized connections and complexity in setting passwords for devices like HEMS and smart meters.
Innovation Solution
An authentication apparatus with a communication unit, verifier, and connection configuration checker that verifies authenticity and determines connection authorization based on the intended destination's address and connection configuration, using authentication relays to facilitate secure network access authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network access authentication methods are used, then authentication processes can be performed, but connection configuration of authentication clients cannot be considered leading to unauthorized connections
Solution Approach 1:
The patent introduces an authentication relay as an intermediary component between the authentication client and the authentication server. The authentication relay receives authentication requests from clients, adds its own address information to the request, and forwards it to the authentication server. This intermediary structure enables the system to consider connection configuration (which home network the client is connected to) without requiring direct modification of the authentication protocol between client and server.
2Reliability
If passwords are set for each home to control smart meter connections, then connection security is improved, but user complexity increases
Solution Approach 1:
The patent implements a self-service mechanism where authentication credentials (passwords) are automatically generated and distributed by the system administrator through the authentication server, eliminating the need for end users to manually set and manage passwords. Each authentication client and smart meter automatically receives their credentials through the authentication relay infrastructure, making the system secure while maintaining ease of operation for users.
3Adaptability or versatility
If free connection is allowed between smart meters, then network flexibility is improved, but unauthorized connections cannot be prevented
Solution Approach 1:
The patent implements preliminary action by performing authentication verification before allowing any connections between smart meters or other devices. The authentication server checks the connection configuration information (which home network the client belongs to) against the authentication relay's address before granting connection permission. This preliminary verification ensures network flexibility is maintained while preventing unauthorized cross-home connections.
Data Source
AI summary
According to one embodiment, there is provided an authentication apparatus, including: a communication unit, a verifier and a connection configuration checker. The communication unit receives a message related to network access authentication on a first communication apparatus, the message including an address of the first communication apparatus and more than zero address of an authentication relay. The verifier verifies an authenticity of the first communication apparatus in response to receipt of the message by the communication unit. The connection configuration checker identifies a first destination to which the first communication apparatus intends to connect, on the basis of the address of the first communication apparatus or the address of the authentication relay included in the message when verification succeeds, and determines whether to authorize connection by the first communication apparatus to the first destination or not.


