Batch Handover Authentication in Heterogeneous Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access authentication protocols in LTE-A and WLAN integrated heterogeneous networks are inefficient for large-scale group access and lack sufficient security, leading to network congestion, high computational overhead, and vulnerability to attacks due to lack of privacy protection.

Innovation Solution

A method for batch handover authentication and key agreement that uses a leader to coordinate the authentication process, aggregating message authentication codes and performing integrity protection to authenticate multiple users simultaneously, reducing system overhead and enhancing security through secure key agreement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each user uses the discovery function module ANDSF to request access gateway information alone, then authentication can be performed individually, but it will cause serious network congestion and consume substantial network resources

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges individual authentication requests into a single batch authentication process. Multiple users are grouped together, and their authentication requests are combined and processed simultaneously by the access gateway, eliminating the need for separate individual authentication requests and thereby reducing network congestion and resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access gateway performs multiple authentication functions simultaneously for multiple users within a single processing cycle. The gateway authenticates multiple users batch-wise, making the authentication system more universal and efficient, capable of handling multiple clients without requiring separate dedicated processing for each user.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If each user uses the discovery function module ANDSF to request access gateway information alone, then individual authentication can be maintained, but computation and communication overheads will increase exponentially

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication computations into a single batch processing operation. Instead of performing separate authentication computations for each user which would lead to exponential growth in computational overhead, the system performs one authentication computation that handles multiple users simultaneously, thereby controlling and reducing the overall computational complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If traditional authentication protocols are used in heterogeneous networks, then basic authentication can be provided, but security level is low and vulnerable to various malicious attacks

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a batch authentication mechanism as an intermediary layer between the users and the access gateway. This intermediary process aggregates multiple user authentication requests and processes them through enhanced security protocols that include privacy protection and resistance against various attacks such as impersonation, man-in-the-middle, replay attacks, and redirection attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security measures including key agreement and privacy protection before the actual authentication process. By establishing secure communication channels and pre-computing authentication parameters in advance, the system prepares the network environment to be resistant to various malicious attacks while maintaining operational simplicity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11665598B2Method for batch handover authentication and key agreement oriented to heterogeneous network
Publication Date: 2023.05.30 SOUTHWEST JIAOTONG UNIV
  • US11665598B2 patent drawing

AI summary

A method for batch handover authentication and key agreement oriented to a heterogeneous network generally includes the following steps: A, system establishment and participant registration: users participating in authentication register on the LTE-A network to obtain their respective identity information; B, access authentication: when a large number of users request access to the WLAN, the target network WLAN is discovered by using the ANDSF, and the leader sends a complete group authentication message to the AAA server of the WLAN to request identity authentication; if the authentication succeeds, the AAA server of the WLAN returns an identity authentication response; C, if the authentication fails, the continued execution of the protocol is terminated. The method effectively realizes batch authentication of users during handover from the LTE-A network to the WLAN, and thus has high authentication efficiency, small signaling overheads, and high security.