Certificateless EAP Authentication Using Prime Number Sequences

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile and wireless authentication mechanisms are not secure, inefficient, and do not meet the performance requirements of 3G mobile communications, particularly in terms of confidentiality, authentication, authorization, and accounting (CAAA), and lack lightweight, certificateless extensible authentication protocols suitable for 2G, 3G, or 4G networks.

Innovation Solution

A system and method using lightweight Extensible Authentication Protocols (EAPs) based on random sequences generated through prime numbers for mobile and wireless communications, which provide certificateless authentication, avoid replay attacks, and offer two-way authentication, utilizing Deterministic Random Sequence Generation (DRSG) and pre-shared keys for secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current mobile and wireless authentication mechanisms use Certificates, then authentication security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate processing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication function from the complex certificate-based PKI system and implements a simplified challenge-response mechanism using pre-shared keys and random number generation. This removes the heavy certificate infrastructure while retaining core authentication security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses disposable session keys and temporary authentication tokens instead of long-lived certificates. Each authentication session generates new random keys that are discarded after use, eliminating the need for complex certificate management while maintaining security.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Device complexity

If lightweight authentication protocols are used, then device complexity is reduced, but security reliability may deteriorate

Engineering Contradiction:
Improveprotocol simplicityVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent performs preliminary key establishment through pre-shared keys before the actual authentication process. This preliminary action secures the subsequent lightweight challenge-response exchange, ensuring that simplicity does not compromise security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces random number generators and challenge-response mechanisms as intermediaries between the simple protocol structure and security requirements. These intermediaries add cryptographic strength without increasing protocol complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If traditional authentication protocols are used, then compatibility with existing systems is improved, but performance and speed deteriorate

Engineering Contradiction:
Improvesystem compatibilityVSAvoidauthentication speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements self-service authentication where devices autonomously generate random challenges and responses using built-in random number generators and pre-shared keys. This eliminates the need for complex certificate verification processes while maintaining compatibility with standard authentication frameworks.

Inventive Principle:
Principle #25Self-service

4Reliability

If certificate-based authentication is implemented, then authentication security is improved, but loss of time and processing overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the essential security elements from certificate-based authentication, keeping the challenge-response mechanism and pre-shared keys while removing the time-consuming certificate verification, parsing, and validation processes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses short-lived session keys and temporary authentication tokens that are generated and discarded quickly during each authentication session. This eliminates the time overhead associated with managing long-lived certificates while maintaining security through frequent key rotation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP2341724B1System and method for secure transaction of data between wireless communication device and server
Publication Date: 2021.03.17 TATA CONSULTANCY SERVICES LTD
  • EP2341724B1 patent drawingFigure 1
  • EP2341724B1 patent drawingFigure 2
  • EP2341724B1 patent drawingFigure 3

AI summary

The present invention provides a system and method for a set of Extensible Authentication Protocols (EAPs) that can serve Confidentiality, Authentication, Authorization and Accounting (CAAA) issues at an affordable cost. According to one embodiment of the invention, a system and method generate random sequences (through prime numbers) which can be used in the authentication process of certificateless extensible authentication protocols (EAPs) for mobile and wireless communications. The invention also provides a light weight security with better performance in comparison to the lower layer chip level security provided by 2G, 3G or 4G applications.