Distributed Authentication for Wireless Distribution Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional AAA systems are inadequate for multi-hop wireless distribution systems, as they require additional relay base stations and central management, leading to complexity and increased processing burden, especially when extending the network or joining isolated systems without compromising security.
Innovation Solution
An authentication method that allows base stations to establish a shared secret with mobile stations independently, using neighbor-supported and multi-hop-supported authentication protocols to distribute authentication management, eliminating the need for a central AAA server and simplifying network extension and isolation joining processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional AAA system is used for authentication, then centralized authentication management is achieved, but the system complexity increases and additional relay base stations are required for multi-hop wireless distribution systems
Solution Approach 1:
The patent segments the centralized authentication function into distributed authentication capabilities at each base station. Each base station independently performs authentication with mobile stations using shared secrets, eliminating the need for a centralized AAA server and reducing system complexity while maintaining authentication reliability
Solution Approach 2:
The patent extracts the authentication management function from the centralized AAA server and relocates it to individual base stations. This extraction removes the dependency on complex centralized infrastructure and enables simpler distributed authentication in multi-hop wireless distribution systems
2Productivity
If additional relay base stations are added to support more mobile stations, then network capacity increases, but the installation complexity increases due to registration requirements
Solution Approach 1:
The patent enables base stations to autonomously establish shared secrets with mobile stations without requiring registration with a central manager. New base stations can independently provide authentication services, eliminating complex installation procedures and enabling easy network expansion
Solution Approach 2:
The patent pre-establishes shared secrets between base stations and mobile stations before network expansion. This allows new base stations to immediately provide authentication services without requiring post-installation registration or configuration, simplifying the installation process
3Reliability
If the main base station acts as a central manager in systems without an AAA server, then authentication is possible, but the processing burden on the main base station increases
Solution Approach 1:
The patent segments the authentication processing burden from the main base station and distributes it to all base stations in the network. Each base station independently handles authentication requests using pre-established shared secrets, eliminating the processing burden on any single base station while maintaining authentication capability
4Adaptability or versatility
If isolated systems are joined together, then network coverage increases, but security management becomes more complex
Solution Approach 1:
The patent implements a universal shared secret mechanism that works across isolated systems. Base stations use the same authentication protocol and shared secret structure regardless of which system they originate from, enabling seamless integration of isolated systems without increasing security management complexity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to an authentication method for wireless distribution system including at least one base station providing access service to mobile stations in a coverage of the base station. In the authentication method, an unregistered base station receives an authentication request from a mobile station, multicast an identity request for identifying the mobile station over the wireless distribution system, receives identity responses from at least one base station in response to the identity request, and performs authentication of the mobile station on the basis of the identity responses. The distributed authentication method of the present invention is performed without AAA server, when a new base station is installed or isolated base stations are joined, such that it is possible to extend the network in an easy manner without degradation of the security degree and additional labor burden of the operator.