Entity Bidirectional Identification for Fast Handoff
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mutual entity authentication methods face challenges in ensuring rapid handoff over communication networks, particularly in scenarios where entities lack valid public keys, leading to complex key management and difficulties in accessing network resources before authentication is complete.
Innovation Solution
A mutual entity authentication method involving two authentication elements and a trusted third party, where all entities within the same element share a public key certificate, simplifying key management by using a trusted third party to verify and distribute public keys, reducing the complexity of network authentication processes and enabling rapid handoff.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional mutual entity authentication methods are used, then authentication security is ensured, but key management complexity increases and authentication time extends
Solution Approach 1:
The patent introduces a trusted third party (TTP) as an intermediary to manage public key distribution and verification. The TTP acts as a mediator between authentication entities, providing public keys and verifying authentication processes, thereby reducing the key management burden on individual entities while maintaining security
Solution Approach 2:
The patent merges the public key management functions into a centralized trusted third party, combining key distribution, verification, and authentication coordination into a single entity. This consolidation reduces the overall system complexity by eliminating redundant key management mechanisms at each authentication entity
2Reliability
If complete authentication protocols are executed, then authentication reliability is improved, but handoff speed decreases
Solution Approach 1:
The patent performs preliminary authentication between authentication entities and the trusted third party before actual handoff operations. Public keys are pre-distributed and verified by the TTP, and authentication relationships are established in advance, allowing rapid handoff without executing complete authentication protocols during mobility events
Solution Approach 2:
The patent implements a dynamic authentication approach where the level of authentication performed adapts based on the operational context. During handoff scenarios, the system leverages pre-established authentication relationships with the TTP to perform lighter-weight verification, while maintaining the option to perform complete authentication when security requirements demand
3Reliability
If public keys are verified during authentication, then authentication security is maintained, but access to network resources before authentication is blocked
Solution Approach 1:
The trusted third party serves as an intermediary that provides public keys to authentication entities before they need to access network resources. This allows entities to obtain necessary cryptographic material without having to complete full authentication first, enabling resource access while maintaining security through the TTP's verification process
Data Source
Figure 1~2
Figure 3~4
AI summary
An entity bidirectional-identification method for supporting fast handoff involves three security elements, which includes two identification elements A and B and a trusted third party (TP). All identification entities of a same element share a public key certification or own a same public key. When any identification entity in identification element A and any identification entity in identification element B need to identify each other, if identification protocol has never been operated between the two identification elements that they belong to respectively, the whole identification protocol process will be operated; otherwise, interaction of identification protocol will be acted only between the two identification entities. Application of the present invention not only centralizes management of public key and simplifies protocol operation condition, but also utilizes the concept of security domain so as to reduce management complexity of public key, shorten identification time and satisfy fast handoff requirements on the premises of guaranteeing security characteristics such as one key for every pair of identification entities, one secret key for every identification and forward secrecy.