EAP Authentication Session Timeout Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional wireless network authentication methods, such as those using IEEE 802.11i and EAP, lead to undesirable disconnections when key lifetimes expire, disrupting active sessions like VoIP due to the need for repeated authentication processes.
Innovation Solution
Incorporating a method where the authentication server generates a session time and communicates a session timeout value to the peer device during the EAP authentication exchange, allowing the peer device to anticipate and initiate a new authentication session before the original session expires, thereby preventing abrupt disconnections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP authentication exchange is used to authenticate peer devices, then network security is improved, but disconnection occurs when key lifetime expires
Solution Approach 1:
The patent applies preliminary action by having the peer device initiate a new authentication exchange before the current key lifetime expires. The device receives the key lifetime value from the authentication server, monitors the expiration time, and proactively starts a new authentication process while the old session is still valid. This prevents abrupt disconnections and ensures continuous network access without interrupting active sessions.
2Reliability
If authentication is repeated after key lifetime expiration, then security is maintained, but active sessions are disrupted
Solution Approach 1:
The patent applies preliminary anti-action by counteracting the potential disruption before it occurs. The peer device monitors the key lifetime and initiates re-authentication while the current session is still active, preventing the de-authentication event that would otherwise disrupt VoIP calls or data transfers. This proactive approach neutralizes the harmful effect of session interruption while maintaining security through continuous authentication.
3Duration of action of stationary object
If key lifetime is extended, then session continuity is improved, but security refresh frequency is reduced
Solution Approach 1:
The patent applies dynamics by making the authentication process adaptive and flexible. Instead of relying on a fixed key lifetime that causes abrupt expirations, the system dynamically initiates new authentication exchanges based on monitored time thresholds. The peer device can adjust its re-authentication timing to overlap with the remaining lifetime of the current session, creating a dynamic transition that maintains both security refresh and session continuity.
Data Source
AI summary
A system and method for authenticating a peer device onto a network using Extensible Authentication Protocol (EAP). The key lifetime associated with the keying material generated in the peer device and the authentication server is communicated from the authenticator to the peer device within the EAP Success message. The peer device, having been provided with the key lifetime, can anticipate the termination of its authenticated session and initiate re-authentication prior to expiry of the key lifetime.


