EAP Success Message Security via Intermediary Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods using Extensible Authentication Protocol (EAP) lack security protection for EAP Success indications and reliability protection for EAP Success messages, making them vulnerable to denial of service attacks and network connection disruptions.
Innovation Solution
A method and system that enhance security and reliability by incorporating acknowledgement and retransmission mechanisms for authentication and access control, using Message Authentication Code (MAC) and time interval information, and enabling intermediaries to perform exchanges without lengthy backend server interactions, while supporting interoperability between EAP and HOKEY protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional EAP authentication is used, then authentication framework is established, but security protection for EAP Success indications is lacking
Solution Approach 1:
The patent introduces an intermediary authentication mechanism between the EAP server and the peer. The server sends EAP Success indications through an intermediary (authenticator) that provides security protection by verifying message authenticity and integrity before forwarding to the peer, thus resolving the security vulnerability in conventional EAP without requiring fundamental protocol changes
Solution Approach 2:
The authentication process is segmented into distinct phases: authentication phase (using conventional EAP), authorization phase (using new security mechanisms), and confirmation phase (using acknowledgment messages). This segmentation allows security enhancements to be added without disrupting the existing EAP authentication flow
2Reliability
If conventional EAP authentication is used, then authentication framework is established, but reliability protection for EAP Success messages is lacking
Solution Approach 1:
The patent implements a feedback mechanism where the peer sends acknowledgment messages to confirm receipt of EAP Success indications. The server receives these acknowledgments and can retransmit EAP Success messages if acknowledgments are not received within a predetermined time, ensuring reliable delivery without adding complex reliability mechanisms to the core EAP protocol
Solution Approach 2:
The system prepares for potential message loss by implementing retransmission mechanisms and acknowledgment confirmations before actual failures occur. The server is configured to retransmit EAP Success messages if acknowledgments are not received within a predetermined time, cushioning against network failures without requiring complex real-time reliability monitoring
3Productivity
If EAP Success messages are sent without acknowledgment, then authentication is faster, but denial of service attacks can occur
Solution Approach 1:
The patent applies partial action by implementing acknowledgment mechanisms only for critical EAP Success messages that require confirmation, while allowing other authentication messages to proceed without acknowledgment. This selective approach provides security against denial of service attacks for essential messages while maintaining fast authentication for less critical operations
4Adaptability or versatility
If intermediaries forward EAP messages without understanding semantics, then network integration is easier, but security control is reduced
Solution Approach 1:
The patent enhances the intermediary's role by providing it with specific security control capabilities while maintaining its message-forwarding function. The intermediary (authenticator) is configured to verify EAP Success message authenticity and integrity before forwarding to the peer, enabling security control without requiring full semantic understanding of the EAP protocol
Solution Approach 2:
The patent applies local quality by providing security control functionality specifically at the intermediary level where it is most needed, rather than requiring all network elements to implement full security mechanisms. The authenticator performs localized security verification for EAP Success messages, enabling security control with minimal impact on overall network complexity
Data Source
AI summary
A method for secure and reliable authentication in a communication system. In an embodiment, the authentication method includes performing authentication of a user utilizing Extensible Authentication Protocol (EAP), and transmitting a result indication message to the user. The result indication message can include additional information for security and reliability. The method also includes receiving an acknowledgement message from the user. The acknowledgement message is sent by the user for confirming the reception of the result indication. In an embodiment, the method also includes retransmitting the result indication message if the acknowledgement message is not received within a predetermined time. The additional information for security and reliability can include Message Authentication Code (MAC) and time interval information. The additional information for security and reliability can also include a security/reliability flag.


