Cryptographic Token Authentication for Heterogeneous Network Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication networks, particularly those using Low-Power Wide-Area (LPWA) technology, face challenges in providing coverage in areas with no infrastructure, such as outdoor regions and indoor spaces with structural damping, limiting the ability of communication devices to connect across different network types.

Innovation Solution

The implementation of communication devices equipped with radio modules and processors that enable efficient authentication and data transmission through a tunneling protocol, allowing communication across heterogeneous networks, including wireless and wired/fixed networks, by appending a cryptographic token independent of the tunneling protocol, which simplifies authentication and reduces processing power consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed using traditional methods in heterogeneous networks, then security is maintained, but processing power consumption increases and battery life decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication verification function from the receiving device and relocates it to the transmitting device. The receiving device only needs to verify a cryptographic token (hash value) rather than performing full authentication processing, significantly reducing its processing power consumption and battery usage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs authentication processing in advance at the transmitting device before data transmission. The transmitting device calculates the cryptographic token based on the data and sends it along with the authenticated data, so the receiving device only needs to perform simple verification rather than full authentication processing.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If communication is limited to homogeneous networks with defined infrastructure, then network management is simplified, but coverage area is restricted

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidcoverage area
Core Design Contradiction:
Adaptability or versatilityVSArea of stationary object

Solution Approach 1:

The patent enables communication devices to operate across multiple network types (homogeneous and heterogeneous networks) by implementing a universal authentication mechanism. The cryptographic token verification method works across different network infrastructures including LoRaWAN, NB-IoT, LTE-M, and traditional cellular networks, allowing devices to communicate wherever network coverage exists.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If full authentication processing is performed at the receiving device, then authentication security is maintained, but device complexity and processing requirements increase

Engineering Contradiction:
Improveauthentication securityVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cryptographic token (hash value) as an intermediary that carries authentication information from the transmitting device to the receiving device. This token allows the receiving device to verify authentication without performing complex authentication processing, effectively delegating the heavy computational burden to the transmitting device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3432536B1Communication device for communicating data via a first communication network with a second communication network using a cryptographic token
Publication Date: 2020.11.18 DEUTSCHE TELEKOM AG
  • EP3432536B1 patent drawingFigure 1
  • EP3432536B1 patent drawingFigure 2
  • EP3432536B1 patent drawingFigure 3a~3b

AI summary

The disclosure relates to a communication device (110a) for communicating data via a first communication network (141) with a second communication network (131), the communication device (110a) comprising: a processor (111) configured to process data (300a, 300b) comprising a payload section (301) and a first header section (302); a memory (113, 115) configured to store the data (300a, 300b); and a radio transmitter (117) configured to transmit the processed data via the first communication network (141) to neighboring communication devices (110b, 110c) of the second communication network (131) and/or a base station (130) of the second communication network (131), wherein the processor (111) is configured to append a second header section (303) to the data (300a, 300b) in accordance with a tunneling protocol (142, 143, 144) for tunneling the data (300a, 300b) through the first communication network (141) to the second communication network (131) and to append a cryptographic token (304) to the data (300a, 300b) to authenticate the payload section (301) of the data, wherein the cryptographic token (304) is independent from the second header section (303).