Certificateless EAP Authentication Using Prime Number Sequences
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile and wireless authentication mechanisms are not secure, inefficient, and do not meet the performance requirements of 3G mobile communications, particularly in terms of confidentiality, authentication, authorization, and accounting (CAAA), and lack lightweight, certificateless extensible authentication protocols suitable for 2G, 3G, or 4G networks.
Innovation Solution
A system and method using lightweight Extensible Authentication Protocols (EAPs) based on random sequences generated through prime numbers for mobile and wireless communications, which provide certificateless authentication, avoid replay attacks, and offer two-way authentication, utilizing Deterministic Random Sequence Generation (DRSG) and pre-shared keys for secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current mobile and wireless authentication mechanisms use Certificates, then authentication security is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent extracts the essential authentication function from the complex certificate-based PKI system and implements a simplified challenge-response mechanism using pre-shared keys and random number generation. This removes the heavy certificate infrastructure while retaining core authentication security.
Solution Approach 2:
The patent uses disposable session keys and temporary authentication tokens instead of long-lived certificates. Each authentication session generates new random keys that are discarded after use, eliminating the need for complex certificate management while maintaining security.
2Device complexity
If lightweight authentication protocols are used, then device complexity is reduced, but security reliability may deteriorate
Solution Approach 1:
The patent performs preliminary key establishment through pre-shared keys before the actual authentication process. This preliminary action secures the subsequent lightweight challenge-response exchange, ensuring that simplicity does not compromise security.
Solution Approach 2:
The patent introduces random number generators and challenge-response mechanisms as intermediaries between the simple protocol structure and security requirements. These intermediaries add cryptographic strength without increasing protocol complexity.
3Adaptability or versatility
If traditional authentication protocols are used, then compatibility with existing systems is improved, but performance and speed deteriorate
Solution Approach 1:
The patent implements self-service authentication where devices autonomously generate random challenges and responses using built-in random number generators and pre-shared keys. This eliminates the need for complex certificate verification processes while maintaining compatibility with standard authentication frameworks.
4Reliability
If certificate-based authentication is implemented, then authentication security is improved, but loss of time and processing overhead increase
Solution Approach 1:
The patent extracts only the essential security elements from certificate-based authentication, keeping the challenge-response mechanism and pre-shared keys while removing the time-consuming certificate verification, parsing, and validation processes.
Solution Approach 2:
The patent uses short-lived session keys and temporary authentication tokens that are generated and discarded quickly during each authentication session. This eliminates the time overhead associated with managing long-lived certificates while maintaining security through frequent key rotation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention provides a system and method for a set of Extensible Authentication Protocols (EAPs) that can serve Confidentiality, Authentication, Authorization and Accounting (CAAA) issues at an affordable cost. According to one embodiment of the invention, a system and method generate random sequences (through prime numbers) which can be used in the authentication process of certificateless extensible authentication protocols (EAPs) for mobile and wireless communications. The invention also provides a light weight security with better performance in comparison to the lower layer chip level security provided by 2G, 3G or 4G applications.