EAP-RP Protocol Single Credential Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users of electronic devices need multiple sets of security credentials to access application access servers through secure corporate or home networks, increasing deployment and support costs due to the complexity of provisioning and authentication processes.

Innovation Solution

Implementing an EAP-RP protocol that allows a single set of credentials to be used for accessing both application access servers and wireless networks, such as corporate WLANs and VPNs, by defining an authentication method that enables keying material generation for secure access via IEEE 802.1X and IKE protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple sets of security credentials are provisioned for accessing different networks and servers, then secure access is maintained, but device complexity and provisioning cost increase

Engineering Contradiction:
Improvesecure accessVSAvoidcredential provisioning
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple credential verification processes into a single EAP-RP authentication flow that simultaneously validates credentials against the authentication server and generates keying material for both network access and application server access, eliminating the need for separate credential sets

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The EAP-RP protocol serves multiple functions: it authenticates the user to the network, generates keying material for secure communication, and enables access to both the WLAN and the application access server using a single credential set, making the authentication system universal across different access points

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication protocols are implemented for different networks, then network security is maintained, but ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The EAP-RP protocol is designed to work over multiple transport mechanisms (WLAN, VPN, wired networks) and supports both EAP and non-EAP authentication methods, providing a universal authentication approach that maintains security while simplifying user interaction across different network types

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If separate credential provisioning is done for each network access point, then access security is ensured, but deployment cost increases

Engineering Contradiction:
Improveaccess securityVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system merges the authentication and key generation functions into a single EAP-RP protocol execution that simultaneously secures both network access and application server access, eliminating the need for separate provisioning processes and reducing deployment complexity and cost

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2612514B1Network access
Publication Date: 2018.05.09 BLACKBERRY LTD
  • EP2612514B1 patent drawingFigure 1
  • EP2612514B1 patent drawingFigure 2
  • EP2612514B1 patent drawingFigure 3

AI summary

A method for network access is provided. The method includes establishing a secure link between a user equipment (UE) and a wireless local area network (WLAN) when an authentication and authorization server determines that credentials provided by the UE to the authentication and authorization server allow the UE secure access to the WLAN. The method further includes establishing a secure link between the UE and an application access server via the WLAN when the application access server, using the same credentials, determines that the UE is allowed secure access to the application access server.