EAP Authentication Session Timeout Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional wireless network authentication methods, such as those using IEEE 802.11i and EAP, lead to undesirable disconnections when key lifetimes expire, disrupting active sessions like VoIP due to the need for repeated authentication processes.

Innovation Solution

Incorporating a method where the authentication server generates a session time and communicates a session timeout value to the peer device during the EAP authentication exchange, allowing the peer device to anticipate and initiate a new authentication session before the original session expires, thereby preventing abrupt disconnections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAP authentication exchange is used to authenticate peer devices, then network security is improved, but disconnection occurs when key lifetime expires

Engineering Contradiction:
Improvenetwork securityVSAvoidsession continuity
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent applies preliminary action by having the peer device initiate a new authentication exchange before the current key lifetime expires. The device receives the key lifetime value from the authentication server, monitors the expiration time, and proactively starts a new authentication process while the old session is still valid. This prevents abrupt disconnections and ensures continuous network access without interrupting active sessions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication is repeated after key lifetime expiration, then security is maintained, but active sessions are disrupted

Engineering Contradiction:
ImprovesecurityVSAvoidsession stability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary anti-action by counteracting the potential disruption before it occurs. The peer device monitors the key lifetime and initiates re-authentication while the current session is still active, preventing the de-authentication event that would otherwise disrupt VoIP calls or data transfers. This proactive approach neutralizes the harmful effect of session interruption while maintaining security through continuous authentication.

Inventive Principle:
Principle #9Preliminary anti-action

3Duration of action of stationary object

If key lifetime is extended, then session continuity is improved, but security refresh frequency is reduced

Engineering Contradiction:
Improvesession continuityVSAvoidsecurity refresh
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The patent applies dynamics by making the authentication process adaptive and flexible. Instead of relying on a fixed key lifetime that causes abrupt expirations, the system dynamically initiates new authentication exchanges based on monitored time thresholds. The peer device can adjust its re-authentication timing to overlap with the remaining lifetime of the current session, creating a dynamic transition that maintains both security refresh and session continuity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9391776B2Method and system for authenticating peer devices using EAP
Publication Date: 2016.07.12 MALIKIE INNOVATIONS LTD
  • US9391776B2 patent drawing
  • US9391776B2 patent drawing
  • US9391776B2 patent drawing

AI summary

A system and method for authenticating a peer device onto a network using Extensible Authentication Protocol (EAP). The key lifetime associated with the keying material generated in the peer device and the authentication server is communicated from the authenticator to the peer device within the EAP Success message. The peer device, having been provided with the key lifetime, can anticipate the termination of its authenticated session and initiate re-authentication prior to expiry of the key lifetime.