Enterprise Key Generation for Fast Roaming Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication networks face challenges in managing network authentication across multiple access types, leading to inconvenient and time-consuming authentications when users switch between different access networks, such as from cellular to Wi-Fi networks, even after completing secondary authentication.

Innovation Solution

The implementation of an enterprise key generation method during authentication allows for fast roaming across various access technologies, including wired and wireless networks, by using a global authentication, authorization, and accounting (AAA) function to manage access and provide authentication information, thereby reducing the need for separate authentications at each access technology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users perform separate authentications at each access technology when switching between cellular and Wi-Fi networks, then network security is maintained, but user convenience deteriorates and authentication time increases

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary authentication through the service provider network first, obtaining authentication credentials in advance. When users switch to Wi-Fi or other access networks, the pre-obtained credentials are reused, eliminating the need for repeated authentication and significantly reducing authentication time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication mechanism is designed to be universal across multiple access technologies. A single authentication process in the service provider network generates credentials that can be used across cellular, Wi-Fi, and other access networks, making the authentication system multi-functional and eliminating the need for separate authentications at each access technology

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If fast roaming is implemented across multiple access networks, then user convenience is improved, but network complexity increases

Engineering Contradiction:
Improveroaming convenienceVSAvoidauthentication system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The service provider network acts as an intermediary that manages authentication credentials and distributes them to users. This intermediary approach simplifies the overall system by centralizing authentication management, allowing users to roam across multiple access networks without each network needing complex authentication capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional components: credential generation at the service provider network, credential distribution to users, and credential verification at access networks. This segmentation allows each component to be optimized independently while maintaining overall system simplicity and enabling fast roaming

Inventive Principle:
Principle #1Segmentation

3Reliability

If secondary authentication is performed during initial connection, then access security is improved, but handover latency increases when switching networks

Engineering Contradiction:
Improveaccess securityVSAvoidhandover speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Secondary authentication is performed as a preliminary action during the initial connection to the service provider network. The authentication credentials obtained in advance are stored and reused during network handovers, maintaining access security while enabling fast roaming without requiring repeated authentication processes during network switching

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11777935B2Extending secondary authentication for fast roaming between service provider and enterprise network
Publication Date: 2023.10.03 CISCO TECHNOLOGY INC
  • US11777935B2 patent drawing
  • US11777935B2 patent drawing
  • US11777935B2 patent drawing

AI summary

Methods are provided for generating an enterprise key for access to an enterprise network via another access network, as part of a secondary authentication to an external data network through another access network. In these methods, an enterprise authentication device obtains, via a first access network, a request to authenticate a user device onto an enterprise network. The user device is connected to the first access network. The method further includes the enterprise authentication device authenticating the user device to obtain access to the enterprise network via the first access network and generating the enterprise key for the user device to provide access to the enterprise network via a second access network.