Enterprise Key Generation for Fast Roaming Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication networks face challenges in managing network authentication across multiple access types, leading to inconvenient and time-consuming authentications when users switch between different access networks, such as from cellular to Wi-Fi networks, even after completing secondary authentication.
Innovation Solution
The implementation of an enterprise key generation method during authentication allows for fast roaming across various access technologies, including wired and wireless networks, by using a global authentication, authorization, and accounting (AAA) function to manage access and provide authentication information, thereby reducing the need for separate authentications at each access technology.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users perform separate authentications at each access technology when switching between cellular and Wi-Fi networks, then network security is maintained, but user convenience deteriorates and authentication time increases
Solution Approach 1:
The system performs preliminary authentication through the service provider network first, obtaining authentication credentials in advance. When users switch to Wi-Fi or other access networks, the pre-obtained credentials are reused, eliminating the need for repeated authentication and significantly reducing authentication time while maintaining security
Solution Approach 2:
The authentication mechanism is designed to be universal across multiple access technologies. A single authentication process in the service provider network generates credentials that can be used across cellular, Wi-Fi, and other access networks, making the authentication system multi-functional and eliminating the need for separate authentications at each access technology
2Ease of operation
If fast roaming is implemented across multiple access networks, then user convenience is improved, but network complexity increases
Solution Approach 1:
The service provider network acts as an intermediary that manages authentication credentials and distributes them to users. This intermediary approach simplifies the overall system by centralizing authentication management, allowing users to roam across multiple access networks without each network needing complex authentication capabilities
Solution Approach 2:
The authentication system is segmented into distinct functional components: credential generation at the service provider network, credential distribution to users, and credential verification at access networks. This segmentation allows each component to be optimized independently while maintaining overall system simplicity and enabling fast roaming
3Reliability
If secondary authentication is performed during initial connection, then access security is improved, but handover latency increases when switching networks
Solution Approach 1:
Secondary authentication is performed as a preliminary action during the initial connection to the service provider network. The authentication credentials obtained in advance are stored and reused during network handovers, maintaining access security while enabling fast roaming without requiring repeated authentication processes during network switching
Data Source
AI summary
Methods are provided for generating an enterprise key for access to an enterprise network via another access network, as part of a secondary authentication to an external data network through another access network. In these methods, an enterprise authentication device obtains, via a first access network, a request to authenticate a user device onto an enterprise network. The user device is connected to the first access network. The method further includes the enterprise authentication device authenticating the user device to obtain access to the enterprise network via the first access network and generating the enterprise key for the user device to provide access to the enterprise network via a second access network.


