Converged Access Node Authentication via Cellular Cipher Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current WiFi access control and secure data transmission methods in converged wireless networks face challenges, particularly in large-scale deployments, where pre-shared key authentication is vulnerable and complex, and 802.1x-based solutions require additional infrastructure and increased system complexity.

Innovation Solution

A method where a converged access node uses the cellular network's unique cipher key for both authenticating and encrypting WiFi access, eliminating the need for shared keys and reducing system complexity by leveraging existing cellular network security mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If pre-shared key authentication is used in WiFi access, then the authentication process is simple and does not require additional infrastructure, but the security is vulnerable and key management becomes complex in large-scale deployments

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines cellular network authentication mechanisms with WiFi access authentication. The access node integrates both cellular and WiFi access functions, allowing the WiFi authentication to leverage the security infrastructure already established for cellular networks. This merging eliminates the need for separate pre-shared key management while maintaining strong security through the cellular network's existing key management system.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If 802.1x-based authentication is used in WiFi access, then the authentication security is improved, but the system complexity increases and additional infrastructure is required

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access node is designed to perform multiple functions: it serves as both a cellular base station and a WiFi access point. By making the access node universal, the patent eliminates the need for separate authentication infrastructure for WiFi, as the same node that provides cellular service also handles WiFi authentication using the cellular network's security mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The cellular network's existing security infrastructure serves the dual purpose of cellular authentication and WiFi authentication. The key management system, authentication protocols, and security policies already in place for cellular networks are reused for WiFi access, eliminating the need for separate 802.1x infrastructure and reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If pre-shared key authentication is used in large-scale WiFi networks, then the deployment is simplified, but the key management becomes cumbersome and security vulnerabilities increase

Engineering Contradiction:
Improvedeployment simplicityVSAvoidkey management complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The cellular network's authentication server acts as an intermediary between the WiFi client and the access node. Instead of direct pre-shared key authentication between the client and access node, the cellular authentication infrastructure mediates the authentication process, providing centralized key management and eliminating the need for manual key distribution in large-scale deployments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2786608B1A method and a system of authentication in a converged wireless network
Publication Date: 2020.04.22 ALCATEL LUCENT SA
  • EP2786608B1 patent drawingFigure 1
  • EP2786608B1 patent drawingFigure 2~3
  • EP2786608B1 patent drawingFigure 4

AI summary

A method and a device of authentication in the converged wireless network In the existing WLAN network, the authentication method using the pre-shared cipher key has low safety, and is not applicable for large scale deployment; while the authentication method based on 802.1x is very complex and needs to introduce EAP/RADIUS servers. The invention provides an authentication method and device in a converged wireless access network, wherein, the wireless access network and the UE all maintain a cipher key of a UE for accessing the first wireless access network, when the UE accessing the second wireless access network, the wireless access network and the UE implements the authentication based on the cipher key. In the invention, the UE key for accessing the first wireless access network, which has been obtained safely, is used in the authentication for the access of the UE in the second wireless access network. Compared to the traditional solution of the shared cipher key, the proposed solution ensures safety; and compared to the traditional 802.1x solution, it saves the operation of obtaining the cipher key via negotiating, and does not need to involve the network element such as key servers etc.