Entity Bidirectional Identification for Fast Handoff

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mutual entity authentication methods face challenges in ensuring rapid handoff over communication networks, particularly in scenarios where entities lack valid public keys, leading to complex key management and difficulties in accessing network resources before authentication is complete.

Innovation Solution

A mutual entity authentication method involving two authentication elements and a trusted third party, where all entities within the same element share a public key certificate, simplifying key management by using a trusted third party to verify and distribute public keys, reducing the complexity of network authentication processes and enabling rapid handoff.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional mutual entity authentication methods are used, then authentication security is ensured, but key management complexity increases and authentication time extends

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted third party (TTP) as an intermediary to manage public key distribution and verification. The TTP acts as a mediator between authentication entities, providing public keys and verifying authentication processes, thereby reducing the key management burden on individual entities while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges the public key management functions into a centralized trusted third party, combining key distribution, verification, and authentication coordination into a single entity. This consolidation reduces the overall system complexity by eliminating redundant key management mechanisms at each authentication entity

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If complete authentication protocols are executed, then authentication reliability is improved, but handoff speed decreases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidhandoff speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs preliminary authentication between authentication entities and the trusted third party before actual handoff operations. Public keys are pre-distributed and verified by the TTP, and authentication relationships are established in advance, allowing rapid handoff without executing complete authentication protocols during mobility events

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic authentication approach where the level of authentication performed adapts based on the operational context. During handoff scenarios, the system leverages pre-established authentication relationships with the TTP to perform lighter-weight verification, while maintaining the option to perform complete authentication when security requirements demand

Inventive Principle:
Principle #15Dynamics

3Reliability

If public keys are verified during authentication, then authentication security is maintained, but access to network resources before authentication is blocked

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted third party serves as an intermediary that provides public keys to authentication entities before they need to access network resources. This allows entities to obtain necessary cryptographic material without having to complete full authentication first, enabling resource access while maintaining security through the TTP's verification process

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2282444B1Entity bidirectional-identification method for supporting fast handoff
Publication Date: 2018.07.04 CHINA IWNCOMM
  • EP2282444B1 patent drawingFigure 1~2
  • EP2282444B1 patent drawingFigure 3~4
  • EP2282444B1 patent drawing

AI summary

An entity bidirectional-identification method for supporting fast handoff involves three security elements, which includes two identification elements A and B and a trusted third party (TP). All identification entities of a same element share a public key certification or own a same public key. When any identification entity in identification element A and any identification entity in identification element B need to identify each other, if identification protocol has never been operated between the two identification elements that they belong to respectively, the whole identification protocol process will be operated; otherwise, interaction of identification protocol will be acted only between the two identification entities. Application of the present invention not only centralizes management of public key and simplifies protocol operation condition, but also utilizes the concept of security domain so as to reduce management complexity of public key, shorten identification time and satisfy fast handoff requirements on the premises of guaranteeing security characteristics such as one key for every pair of identification entities, one secret key for every identification and forward secrecy.