Subscriber Station Authentication Mode Negotiation in Wireless Portable Internet

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing authentication standards for subscriber stations in wireless portable Internet systems, as defined by IEEE 802.16, are inadequate for supporting mobility and require additional functions in base stations, particularly for handling subscriber profiles and security key distribution, which limits their ability to interwork with different networks.

Innovation Solution

A method is introduced that allows subscriber stations to negotiate an authentication mode with base stations using basic capability negotiation messages, enabling either IEEE 802.16 privacy standard protocol or standardized upper-layer authentication protocols like EAP-TLS and EAP-TTLS, and involves an AAA server for authenticating subscribers, facilitating seamless handovers and secure key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the IEEE 802.16 privacy standard protocol is used for subscriber station authentication, then authentication functions are established for stations in wide area network, but the authentication function is inappropriate for subscriber stations supporting mobility and requires additional base station functions

Engineering Contradiction:
Improveauthentication functionVSAvoidmobility support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic authentication mode negotiation between base station and subscriber station. The system can switch between IEEE 802.16 privacy mode and upper layer standardized protocol mode based on mobility requirements. This dynamic adaptation allows the authentication system to be flexible enough to support both fixed and mobile subscriber stations without requiring additional base station functions for mobility support.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the authentication mode parameter from a fixed IEEE 802.16 privacy standard to a negotiable parameter that can select between different authentication protocols. By making the authentication mode a configurable parameter rather than a fixed standard, the system can adapt to different mobility scenarios and network types, resolving the contradiction between authentication reliability and mobility adaptability.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If additional base station functions are required for mobile services, then authentication can support mobility, but base station complexity increases due to requiring profiles of all subscribers and API functions

Engineering Contradiction:
Improvemobility supportVSAvoidbase station function
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication profile storage and management functions from the base station and relocates them to external authentication servers (AAA servers). The base station only retains the function of initiating and managing the authentication process, while the actual subscriber profile data and complex authentication logic are handled by dedicated authentication servers. This extraction significantly reduces base station complexity while maintaining mobility support capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces authentication servers as intermediary components between the base station and subscriber stations. These servers act as mediators that handle the complex tasks of storing subscriber profiles, verifying credentials, and managing authentication state. The base station communicates with these intermediaries using standardized protocols, avoiding the need to implement complex authentication management functions locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If conventional digital certificate-based authentication is used, then authentication security is established, but the authentication process is restricted to certificate-based servers and requires additional security functions

Engineering Contradiction:
Improveauthentication securityVSAvoidprotocol flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the authentication protocol dynamic and negotiable rather than fixed to digital certificates. The base station and subscriber station can negotiate to use either IEEE 802.16 privacy mode or upper layer standardized protocols such as EAP-TLS, EAP-TTLS, or PAP/CHAP. This dynamic protocol selection maintains security through established standards while providing versatility to work with different authentication servers and network types.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal authentication framework that can handle multiple authentication methods through a single negotiation mechanism. The base station is designed to support both IEEE 802.16 privacy authentication and upper layer standardized protocols, making it multi-functional. This universal approach allows the same base station infrastructure to serve diverse authentication scenarios without requiring separate systems for each protocol.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If base station distributes security key between subscriber station and base station, then authentication is completed, but security vulnerability increases due to key distribution requirements

Engineering Contradiction:
Improveauthentication completionVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces authentication servers as secure intermediaries that handle sensitive key material and credential verification. Instead of the base station directly distributing security keys to subscriber stations, the authentication server mediates the key exchange and verification process. This intermediary approach centralizes security management, reduces the attack surface, and allows for more secure key distribution mechanisms implemented in dedicated security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8140054B2Method for authenticating subscriber station, method for configuring protocol thereof, and apparatus thereof in wireless portable internet system
Publication Date: 2012.03.20 SAMSUNG ELECTRONICS CO LTD
  • US8140054B2 patent drawing
  • US8140054B2 patent drawing
  • US8140054B2 patent drawing

AI summary

Disclosed are a subscriber station authentication method, a protocol configuration method, and a device thereof in a wireless portable Internet system. In the subscriber station authentication method, an authentication mode between a subscriber station (10) and a base station (20) is negotiated, and the authentication mode is negotiated by the base station (20) according to the authentication mode negotiation. The authentication modes include an authentication mode based on the IEEE 802.16 privacy standard protocol and an authentication mode based on the standardized authentication protocol of the upper layer. Authentication is performed by the base station (10) in the case of the authentication mode based on the IEEE 802.16 privacy standard protocol, and the authentication is performed through message transmission using a diameter protocol between a base station (10) and an authentication server (40) in the case of the authentication mode based on the standardized authentication protocol of the upper layer.