Dynamic Authentication Protocol Negotiation in Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless telecommunications networks face limitations in negotiating and selecting appropriate authentication protocols and credentials, restricting entities to specific forms of authentication and credentials, which can hinder seamless user equipment (UE) access to services.
Innovation Solution
The system enables UE, service provider (SP), and authentication endpoint (AEP) to negotiate and select acceptable authentication protocols and credentials, allowing for flexible authentication method selection within Generic Bootstrapping Architectures (GBA) and OpenID federated identity management frameworks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network entities are restricted to using certain forms of authentication and credentials, then security control and management are simplified, but authentication flexibility and adaptability are reduced
Solution Approach 1:
The patent implements dynamic authentication protocol selection where the UE and AEP automatically negotiate and select from multiple supported authentication protocols (AKA, EAP, GBA) based on real-time network conditions and capabilities, rather than being statically restricted to a single protocol. This dynamic adaptation resolves the contradiction by providing flexibility without requiring manual configuration complexity.
Solution Approach 2:
The system changes authentication parameters (protocol type, credentials) based on negotiated capabilities between UE and AEP. The UE indicates supported protocols and credentials, the AEP determines acceptable options, and they negotiate to select the optimal combination, allowing the system to adapt authentication parameters dynamically while maintaining manageable complexity through automated negotiation.
2Ease of operation
If automated negotiation between UE and AEP is implemented to select authentication protocols, then authentication flexibility and user access capability are improved, but communication overhead and negotiation time increase
Solution Approach 1:
The UE prepares authentication capability information in advance by indicating supported authentication protocols and credentials before the actual authentication process begins. This preliminary action allows the AEP to determine acceptable options more efficiently, reducing negotiation time while maintaining flexibility. The UE has already identified its capabilities, so the negotiation process starts from a point of mutual understanding rather than complete discovery.
3Adaptability or versatility
If multiple authentication protocols and credentials are supported, then authentication versatility is enhanced, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent implements a universal authentication framework where both UE and AEP are designed to support multiple authentication protocols (AKA, EAP, GBA) and credential types within a single system architecture. This multi-functional design allows the same system to handle diverse authentication methods without requiring separate specialized systems for each protocol, thereby enhancing versatility while managing implementation complexity through standardized interfaces and negotiation mechanisms.
Data Source
AI summary
Wireless telecommunications networks may implement various forms of authentication. There are a variety of different user and device authentication protocols that follow a similar network architecture, involving various network entities such as a user equipment (UE), a service provider (SP), and an authentication endpoint (AEP). To select an acceptable authentication protocol or credential for authenticating a user or UE, authentication protocol negotiations may take place between various network entities. For example, negotiations may take place in networks implementing a single-sign on (SSO) architecture and/or networks implementing a Generic Bootstrapping Architecture (GBA).


