Certificate-Based Authentication for Small Cell Wireless Stations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless network systems face challenges in securely and efficiently managing the authentication and authorization of small cell wireless stations connecting to controlled access networks, particularly in ensuring secure access and maintaining network integrity.

Innovation Solution

A certificate-based authentication system using a small cell wireless station approved set data structure, where a CMP server validates and issues operational certificates to authorized stations, and a Security Gateway establishes secure tunnels for access, while a provisioning system manages the data structure for approved stations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for small cell wireless stations, then the authentication process is simpler, but network security and access control are weakened

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-registering small cell wireless stations with the CMP server before they attempt to access the network. The CMP server stores authentication credentials and generates certificates in advance, so that when a station attempts to connect, the authentication process is streamlined while maintaining high security. This resolves the contradiction by preparing authentication data beforehand, reducing real-time complexity while ensuring reliable security validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The CMP server acts as an intermediary between small cell wireless stations and the network. It mediates the authentication process by verifying station credentials, generating certificates, and communicating authorization decisions. This intermediary approach enhances network security through centralized control while managing authentication complexity in a standardized manner, resolving the contradiction between security and system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If certificate-based authentication is implemented for all stations, then network security is improved, but the authentication process time increases

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs certificate generation and authentication credential setup in advance during the station registration phase. When a small cell wireless station attempts to access the network, the CMP server already has pre-configured authentication data, allowing for rapid verification. This preliminary preparation reduces the time required during actual authentication while maintaining strong security through certificate-based validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces traditional mechanical authentication methods (such as manual credential verification) with automated electronic certificate validation. The CMP server automatically verifies station credentials and generates certificates through electronic processes, significantly reducing authentication time while maintaining or enhancing security. This substitution of automated electronic verification for manual processes resolves the contradiction between security and authentication speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual management of approved stations is used, then the system is easier to operate, but network integrity and security management are compromised

Engineering Contradiction:
Improvenetwork integrityVSAvoidstation management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The CMP server provides self-service functionality by automatically managing the registration, authentication, and certificate generation for small cell wireless stations. When a station attempts to connect, the server autonomously verifies its credentials against the approved set, generates appropriate certificates, and establishes authorization without requiring manual intervention. This automation maintains network integrity through consistent security policies while significantly improving operational ease by eliminating manual management tasks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11196630B2Certificate-based authentication in networks employing small cell wireless stations
Publication Date: 2021.12.07 VERIZON PATENT & LICENSING INC
  • US11196630B2 patent drawing
  • US11196630B2 patent drawing
  • US11196630B2 patent drawing

AI summary

At least one network device receives a first network address of a first small cell wireless station that has been registered as an authorized wireless station for network access to a target network. The at least one network device adds the first network address of the first small cell wireless station to a small cell wireless station data structure that lists a plurality of network addresses associated with a plurality of authorized small cell wireless stations, and validates, upon power-up of the first small cell wireless station, the first small cell wireless station against the small cell wireless station data structure to selectively establish a first tunnel, between the first small cell wireless station and a gateway connected to the target network, to enable network access to the target network.