EAP Success Message Security via Intermediary Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods using Extensible Authentication Protocol (EAP) lack security protection for EAP Success indications and reliability protection for EAP Success messages, making them vulnerable to denial of service attacks and network connection disruptions.

Innovation Solution

A method and system that enhance security and reliability by incorporating acknowledgement and retransmission mechanisms for authentication and access control, using Message Authentication Code (MAC) and time interval information, and enabling intermediaries to perform exchanges without lengthy backend server interactions, while supporting interoperability between EAP and HOKEY protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional EAP authentication is used, then authentication framework is established, but security protection for EAP Success indications is lacking

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism between the EAP server and the peer. The server sends EAP Success indications through an intermediary (authenticator) that provides security protection by verifying message authenticity and integrity before forwarding to the peer, thus resolving the security vulnerability in conventional EAP without requiring fundamental protocol changes

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct phases: authentication phase (using conventional EAP), authorization phase (using new security mechanisms), and confirmation phase (using acknowledgment messages). This segmentation allows security enhancements to be added without disrupting the existing EAP authentication flow

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional EAP authentication is used, then authentication framework is established, but reliability protection for EAP Success messages is lacking

Engineering Contradiction:
Improvereliability protectionVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the peer sends acknowledgment messages to confirm receipt of EAP Success indications. The server receives these acknowledgments and can retransmit EAP Success messages if acknowledgments are not received within a predetermined time, ensuring reliable delivery without adding complex reliability mechanisms to the core EAP protocol

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system prepares for potential message loss by implementing retransmission mechanisms and acknowledgment confirmations before actual failures occur. The server is configured to retransmit EAP Success messages if acknowledgments are not received within a predetermined time, cushioning against network failures without requiring complex real-time reliability monitoring

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Productivity

If EAP Success messages are sent without acknowledgment, then authentication is faster, but denial of service attacks can occur

Engineering Contradiction:
Improveauthentication speedVSAvoiddenial of service attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies partial action by implementing acknowledgment mechanisms only for critical EAP Success messages that require confirmation, while allowing other authentication messages to proceed without acknowledgment. This selective approach provides security against denial of service attacks for essential messages while maintaining fast authentication for less critical operations

Inventive Principle:
Principle #16Partial or excessive action

4Adaptability or versatility

If intermediaries forward EAP messages without understanding semantics, then network integration is easier, but security control is reduced

Engineering Contradiction:
Improvenetwork integrationVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent enhances the intermediary's role by providing it with specific security control capabilities while maintaining its message-forwarding function. The intermediary (authenticator) is configured to verify EAP Success message authenticity and integrity before forwarding to the peer, enabling security control without requiring full semantic understanding of the EAP protocol

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies local quality by providing security control functionality specifically at the intermediary level where it is most needed, rather than requiring all network elements to implement full security mechanisms. The authenticator performs localized security verification for EAP Success messages, enabling security control with minimal impact on overall network complexity

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8285990B2Method and system for authentication confirmation using extensible authentication protocol
Publication Date: 2012.10.09 FUTUREWEI TECHNOLOGIES INC
  • US8285990B2 patent drawing
  • US8285990B2 patent drawing
  • US8285990B2 patent drawing

AI summary

A method for secure and reliable authentication in a communication system. In an embodiment, the authentication method includes performing authentication of a user utilizing Extensible Authentication Protocol (EAP), and transmitting a result indication message to the user. The result indication message can include additional information for security and reliability. The method also includes receiving an acknowledgement message from the user. The acknowledgement message is sent by the user for confirming the reception of the result indication. In an embodiment, the method also includes retransmitting the result indication message if the acknowledgement message is not received within a predetermined time. The additional information for security and reliability can include Message Authentication Code (MAC) and time interval information. The additional information for security and reliability can also include a security/reliability flag.