Wired LAN Security Access Control via Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security access protocols for wired local area networks primarily focus on validating the terminal's identity by the network, failing to achieve mutual authentication between the terminal and the network, leading to vulnerabilities such as man-in-the-middle attacks and unauthorized access.

Innovation Solution

The Tri-element Peer Authentication (TePA) method and system implement a security access control mechanism that enables mutual authentication between a user and a network, incorporating a certificate-based authentication protocol (TAEP-CAAP) for direct identity authentication and dynamic key negotiation, supporting various network architectures and authentication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If IEEE 802.1x authentication protocol is used with authentication server, then terminal identity validation is improved, but mutual authentication capability deteriorates

Engineering Contradiction:
Improveidentity validation accuracyVSAvoidmutual authentication capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The access point acts as an intermediary entity that performs both terminal authentication and network authentication. It receives authentication requests from terminals, validates them against the authentication server, and simultaneously validates its own identity to terminals, thereby enabling mutual authentication without requiring the terminal to directly authenticate with the network infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access point is designed with multi-functionality, serving both as an authentication client (communicating with the authentication server) and as an authentication server (validating terminal identities and providing security services to terminals). This universal role allows a single entity to perform multiple authentication functions that previously required separate components

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If security patches are added to existing architecture, then security vulnerability remediation is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity vulnerability remediationVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication actions by having the access point validate its own identity and establish security parameters before actual data transmission begins. This proactive approach ensures security is built into the foundation of the connection rather than added as reactive patches later

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security architecture is designed to be dynamic, with the access point able to adapt its authentication behavior based on the terminal's capabilities and the security requirements of the network. This allows the system to provide enhanced security when needed while maintaining compatibility with various terminal types, avoiding the need for complex static security configurations

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2469788B1Security access control method and system for wired local area network
Publication Date: 2018.08.01 CHINA IWNCOMM
  • EP2469788B1 patent drawingFigure 1~2
  • EP2469788B1 patent drawingFigure 3~4

AI summary

The present invention relates to a security access control method and system for wired local area network, the method includes the following steps: 1) a requester (REQ) negotiates the security policy with an authentication access controller (AAC); 2) the requester (REQ) and the authentication access controller (AAC) authenticate the identity; 3) the requester (REQ) negotiates the key with the authentication access controller (AAC). The direct identity authentication between the user and the network access control device is realized by the present invention; the negotiation and the dynamic update of the session key for the link layer data protection are realized; a variety of network architectures such as the enterprise network, the telecommunication network are supported; the scalability is good, the multiple authentication methods are supported; the authentication protocols with different security levels are supported, the requirements of the various subscribers are satisfied; the sub-modules of the protocol are independent, flexible, and easy to be accepted or rejected.