EAP Message Address Swapping for Residential Gateway Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in Fixed Broadband Networks, such as DHCP and PPP, fail to individually authenticate devices like set-top-boxes, VoIP phones, and laptops behind a residential gateway, and are not secure, especially when 3G devices connect via Wi-Fi, leading to challenges in access control, security, and service provision.

Innovation Solution

A method and system that swap destination and source addresses in EAP messages between devices and an authentication server, using the 802.1x protocol without modification, to enable authentication of devices behind a residential gateway in Fixed Broadband networks, allowing for secure and individual device authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current authentication methods (DHCP, PPP) are used, then network access is provided, but individual device authentication is not achieved and security is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary component that mediates between devices and the network. This server implements the 802.1x authentication protocol, providing individual device authentication without requiring complex modifications to existing network infrastructure. The intermediary handles the authentication logic centrally, improving security while maintaining manageable system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameter from network-wide authentication (DHCP, PPP) to individual device authentication using 802.1x protocols. This parameter change enables secure device-level authentication while leveraging existing standardized protocols, avoiding the need to create entirely new complex authentication systems.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If 802.1x protocol is used without modification, then compatibility with existing infrastructure is maintained, but authentication of devices behind residential gateway is enabled

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidauthentication architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication architecture into distinct functional components: residential gateways that maintain existing 802.1x compatibility, authentication servers that handle device authentication, and network infrastructure that enforces authentication policies. This segmentation allows each component to operate independently with standard protocols, achieving device-level authentication without modifying existing infrastructure or increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If individual device authentication is implemented, then security and service differentiation are improved, but existing authentication methods fail to support it

Engineering Contradiction:
Improveaccess controlVSAvoidservice differentiation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication framework based on 802.1x that can authenticate any device type (set-top boxes, VoIP phones, laptops, 3G devices) through a common protocol. This universal approach provides individual device authentication and enables service differentiation without requiring device-specific authentication mechanisms, improving both access control and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2572491B1Systems and methods for host authentication
Publication Date: 2020.03.18 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2572491B1 patent drawingFigure 1
  • EP2572491B1 patent drawingFigure 2
  • EP2572491B1 patent drawingFigure 3

AI summary

Systems and methods provide for authenticating a device. A method for authenticating a device can include receiving, at communications node, a first message, wherein the first message includes a first Extensible Authentication Protocol (EAP) packet which includes an EAP (Identify) ID response and a first destination address; generating, by the communications node, a second message, wherein the second message includes the first EAP ID response and a second destination address which is different from the first destination address; and transmitting, by the communications node, the second message toward the second destination address.