Device Authentication via Identifier Comparison Across Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Public safety communication devices using private shared keys (PSKs) are susceptible to compromise, allowing unauthorized access to secure communications, as stolen devices can be used to access secure networks and PSKs can be copied or transferred.
Innovation Solution
A system and method for authenticating communication devices with an application server that compares unique identifiers across different communication networks to grant or deny access, using a gateway registration port and gateway server port to ensure only authorized devices access the secure network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private shared keys (PSKs) are used to secure communications, then communication security is improved, but device compromise vulnerability increases allowing unauthorized access
Solution Approach 1:
The patent extracts the authentication capability from the physical device by implementing a separate authentication mechanism that does not rely on PSKs stored in the device. The authentication is performed by comparing device identifiers against a registered identifier in the network, separating the authentication function from the communication security key storage.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism between the device and the secure network. Instead of directly using PSKs for authentication, the system uses device identifiers as intermediaries to verify device legitimacy, adding a layer of security that prevents unauthorized access even if PSKs are compromised.
2Ease of operation
If stolen devices can access secure networks, then ease of operation is improved for legitimate users, but unauthorized access risk increases
Solution Approach 1:
The patent implements a feedback mechanism where the network continuously verifies device identifiers against registered identifiers before granting access. This feedback loop ensures that only authenticated devices can access the network, providing real-time verification that prevents unauthorized access while maintaining ease of operation for legitimate devices.
Solution Approach 2:
The patent performs preliminary authentication by registering device identifiers before the devices need to access the secure network. This preliminary action creates an authorization database that enables rapid verification of device legitimacy, allowing legitimate users to access the network easily while blocking unauthorized devices.
3Reliability
If PSKs are stored in communication devices, then authentication capability is improved, but security vulnerability increases when devices are stolen or compromised
Solution Approach 1:
The patent extracts the authentication verification function from the device itself and relocates it to the network side. Instead of relying on PSKs stored in the device for authentication, the system extracts the authentication capability by comparing device identifiers against registered identifiers in the network, removing the security vulnerability associated with storing authentication credentials in potentially compromised devices.
Data Source
AI summary
A method and system for authenticating a communication device with an application server. The application server includes a gateway registration port, a gateway server port, and an electronic processor. The electronic processor is configured to receive, via the gateway registration port, a registration request, including a unique identifier, from a first device over a first communications network that operates in accordance with a first modality and receive, at the gateway server port, an access request including an identifier from an unknown device over a second communications network that operates in accordance with a second modality. The electronic processor is configured to compare the second identifier with the first identifier to determine if the identifiers match, grant the unknown device access when the identifiers match, and deny the unknown device access when the identifiers do not match.


