Dynamic Authentication Protocol Negotiation in Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless telecommunications networks face limitations in negotiating and selecting appropriate authentication protocols and credentials, restricting entities to specific forms of authentication and credentials, which can hinder seamless user equipment (UE) access to services.

Innovation Solution

The system enables UE, service provider (SP), and authentication endpoint (AEP) to negotiate and select acceptable authentication protocols and credentials, allowing for flexible authentication method selection within Generic Bootstrapping Architectures (GBA) and OpenID federated identity management frameworks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network entities are restricted to using certain forms of authentication and credentials, then security control and management are simplified, but authentication flexibility and adaptability are reduced

Engineering Contradiction:
Improveauthentication protocol selection flexibilityVSAvoidauthentication negotiation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication protocol selection where the UE and AEP automatically negotiate and select from multiple supported authentication protocols (AKA, EAP, GBA) based on real-time network conditions and capabilities, rather than being statically restricted to a single protocol. This dynamic adaptation resolves the contradiction by providing flexibility without requiring manual configuration complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (protocol type, credentials) based on negotiated capabilities between UE and AEP. The UE indicates supported protocols and credentials, the AEP determines acceptable options, and they negotiate to select the optimal combination, allowing the system to adapt authentication parameters dynamically while maintaining manageable complexity through automated negotiation.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If automated negotiation between UE and AEP is implemented to select authentication protocols, then authentication flexibility and user access capability are improved, but communication overhead and negotiation time increase

Engineering Contradiction:
Improveuser authentication accessibilityVSAvoidauthentication negotiation time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The UE prepares authentication capability information in advance by indicating supported authentication protocols and credentials before the actual authentication process begins. This preliminary action allows the AEP to determine acceptable options more efficiently, reducing negotiation time while maintaining flexibility. The UE has already identified its capabilities, so the negotiation process starts from a point of mutual understanding rather than complete discovery.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple authentication protocols and credentials are supported, then authentication versatility is enhanced, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveauthentication method diversityVSAvoidsystem implementation ease
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal authentication framework where both UE and AEP are designed to support multiple authentication protocols (AKA, EAP, GBA) and credential types within a single system architecture. This multi-functional design allows the same system to handle diverse authentication methods without requiring separate specialized systems for each protocol, thereby enhancing versatility while managing implementation complexity through standardized interfaces and negotiation mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8914636B2Automated negotiation and selection of authentication protocols
Publication Date: 2014.12.16 INTERDIGITAL PATENT HOLDINGS INC
  • US8914636B2 patent drawing
  • US8914636B2 patent drawing
  • US8914636B2 patent drawing

AI summary

Wireless telecommunications networks may implement various forms of authentication. There are a variety of different user and device authentication protocols that follow a similar network architecture, involving various network entities such as a user equipment (UE), a service provider (SP), and an authentication endpoint (AEP). To select an acceptable authentication protocol or credential for authenticating a user or UE, authentication protocol negotiations may take place between various network entities. For example, negotiations may take place in networks implementing a single-sign on (SSO) architecture and/or networks implementing a Generic Bootstrapping Architecture (GBA).