Inverse Port Authentication for Service Node Network Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital network authentication methods, such as IEEE 802.1x, primarily authenticate client devices, whereas service providers need a mechanism to ensure that new equipment added to the network, like service nodes, are authorized and do not interfere with the normal authentication process of customer premises equipment.

Innovation Solution

A service node that authenticates the network using the Extensible Authentication Protocol (EAP), issuing an authentication request to the network node and determining if the network is authentic, ensuring it only operates with authorized networks and transparently passes data without interfering with conventional authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a service node is added to provide new services, then service functionality is improved, but network security risk increases due to potential unauthorized equipment

Engineering Contradiction:
Improveservice functionalityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent inverts the traditional authentication model by implementing inverse port authentication where the service node authenticates the network node instead of the network node authenticating the service node. This allows new service nodes to be added flexibly while maintaining security, as each service node can verify it is connected to a legitimate network node before providing services

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If conventional authentication methods are used, then client device security is improved, but service node authorization cannot be verified

Engineering Contradiction:
Improveclient device securityVSAvoidservice node authorization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication process into two distinct phases: first, the network node authenticates the service node using conventional methods to ensure client device security; second, the service node authenticates the network node using inverse port authentication to verify service node authorization. This segmentation allows both requirements to be satisfied simultaneously

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If new equipment is added to support new services, then service capability is improved, but authentication process complexity increases

Engineering Contradiction:
Improveservice capabilityVSAvoidauthentication process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework that handles both conventional authentication (network authenticating service node) and inverse port authentication (service node authenticating network) through a single EAP-based protocol. This multi-functionality allows the system to support diverse service nodes with different capabilities while maintaining a unified authentication process

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8301115B1Method for inverse port-based authentication
Publication Date: 2012.10.30 ALCATEL LUCENT SA
  • US8301115B1 patent drawing
  • US8301115B1 patent drawing
  • US8301115B1 patent drawing

AI summary

A service node authenticates a service provider network to which it is connected. When the service node is connected between subscriber devices and a network node of the service provider network, the service node issues an authentication request to the network node. The network node responds to the authentication request by transmitting a reply. The service node receives the reply and determines if it indicates the service provider network to which the service node is connected is authentic. These authentication communications can conform to a standard authentication protocol, such as Extensible Authentication Protocol (EAP). If the reply indicates the service provider network is authentic, the service node permits communication between the subscriber devices and the service provider network. If the reply indicates the service provider network is not authentic, the service node blocks such communication.