Wired LAN Security Access Control via Mutual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security access protocols for wired local area networks primarily focus on validating the terminal's identity by the network, failing to achieve mutual authentication between the terminal and the network, leading to vulnerabilities such as man-in-the-middle attacks and unauthorized access.
Innovation Solution
The Tri-element Peer Authentication (TePA) method and system implement a security access control mechanism that enables mutual authentication between a user and a network, incorporating a certificate-based authentication protocol (TAEP-CAAP) for direct identity authentication and dynamic key negotiation, supporting various network architectures and authentication protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If IEEE 802.1x authentication protocol is used with authentication server, then terminal identity validation is improved, but mutual authentication capability deteriorates
Solution Approach 1:
The access point acts as an intermediary entity that performs both terminal authentication and network authentication. It receives authentication requests from terminals, validates them against the authentication server, and simultaneously validates its own identity to terminals, thereby enabling mutual authentication without requiring the terminal to directly authenticate with the network infrastructure
Solution Approach 2:
The access point is designed with multi-functionality, serving both as an authentication client (communicating with the authentication server) and as an authentication server (validating terminal identities and providing security services to terminals). This universal role allows a single entity to perform multiple authentication functions that previously required separate components
2Reliability
If security patches are added to existing architecture, then security vulnerability remediation is improved, but system complexity increases
Solution Approach 1:
The system performs preliminary authentication actions by having the access point validate its own identity and establish security parameters before actual data transmission begins. This proactive approach ensures security is built into the foundation of the connection rather than added as reactive patches later
Solution Approach 2:
The security architecture is designed to be dynamic, with the access point able to adapt its authentication behavior based on the terminal's capabilities and the security requirements of the network. This allows the system to provide enhanced security when needed while maintaining compatibility with various terminal types, avoiding the need for complex static security configurations
Data Source
Figure 1~2
Figure 3~4
AI summary
The present invention relates to a security access control method and system for wired local area network, the method includes the following steps: 1) a requester (REQ) negotiates the security policy with an authentication access controller (AAC); 2) the requester (REQ) and the authentication access controller (AAC) authenticate the identity; 3) the requester (REQ) negotiates the key with the authentication access controller (AAC). The direct identity authentication between the user and the network access control device is realized by the present invention; the negotiation and the dynamic update of the session key for the link layer data protection are realized; a variety of network architectures such as the enterprise network, the telecommunication network are supported; the scalability is good, the multiple authentication methods are supported; the authentication protocols with different security levels are supported, the requirements of the various subscribers are satisfied; the sub-modules of the protocol are independent, flexible, and easy to be accepted or rejected.