Converged Access Node Authentication via Cellular Cipher Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current WiFi access control and secure data transmission methods in converged wireless networks face challenges, particularly in large-scale deployments, where pre-shared key authentication is vulnerable and complex, and 802.1x-based solutions require additional infrastructure and increased system complexity.
Innovation Solution
A method where a converged access node uses the cellular network's unique cipher key for both authenticating and encrypting WiFi access, eliminating the need for shared keys and reducing system complexity by leveraging existing cellular network security mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If pre-shared key authentication is used in WiFi access, then the authentication process is simple and does not require additional infrastructure, but the security is vulnerable and key management becomes complex in large-scale deployments
Solution Approach 1:
The patent combines cellular network authentication mechanisms with WiFi access authentication. The access node integrates both cellular and WiFi access functions, allowing the WiFi authentication to leverage the security infrastructure already established for cellular networks. This merging eliminates the need for separate pre-shared key management while maintaining strong security through the cellular network's existing key management system.
2Reliability
If 802.1x-based authentication is used in WiFi access, then the authentication security is improved, but the system complexity increases and additional infrastructure is required
Solution Approach 1:
The access node is designed to perform multiple functions: it serves as both a cellular base station and a WiFi access point. By making the access node universal, the patent eliminates the need for separate authentication infrastructure for WiFi, as the same node that provides cellular service also handles WiFi authentication using the cellular network's security mechanisms.
Solution Approach 2:
The cellular network's existing security infrastructure serves the dual purpose of cellular authentication and WiFi authentication. The key management system, authentication protocols, and security policies already in place for cellular networks are reused for WiFi access, eliminating the need for separate 802.1x infrastructure and reducing overall system complexity.
3Ease of manufacture
If pre-shared key authentication is used in large-scale WiFi networks, then the deployment is simplified, but the key management becomes cumbersome and security vulnerabilities increase
Solution Approach 1:
The cellular network's authentication server acts as an intermediary between the WiFi client and the access node. Instead of direct pre-shared key authentication between the client and access node, the cellular authentication infrastructure mediates the authentication process, providing centralized key management and eliminating the need for manual key distribution in large-scale deployments.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A method and a device of authentication in the converged wireless network In the existing WLAN network, the authentication method using the pre-shared cipher key has low safety, and is not applicable for large scale deployment; while the authentication method based on 802.1x is very complex and needs to introduce EAP/RADIUS servers. The invention provides an authentication method and device in a converged wireless access network, wherein, the wireless access network and the UE all maintain a cipher key of a UE for accessing the first wireless access network, when the UE accessing the second wireless access network, the wireless access network and the UE implements the authentication based on the cipher key. In the invention, the UE key for accessing the first wireless access network, which has been obtained safely, is used in the authentication for the access of the UE in the second wireless access network. Compared to the traditional solution of the shared cipher key, the proposed solution ensures safety; and compared to the traditional 802.1x solution, it saves the operation of obtaining the cipher key via negotiating, and does not need to involve the network element such as key servers etc.