Mutual Authentication Messaging in IEEE 802.11 Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mutual authentication in networks requires extensive messaging between nodes and a server, leading to inefficiencies in communication.

Innovation Solution

A method and apparatus for mutual authentication between nodes in a network that reduces messaging by sending and receiving combined authentication messages containing necessary information for both nodes to authenticate each other, utilizing a peer-to-peer network architecture and IEEE 802.11 protocol modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full authentication exchange with server is performed for mutual authentication, then authentication reliability is improved, but messaging quantity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidmessaging quantity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines two separate authentication exchanges into a single integrated authentication message. Instead of Node A performing a full authentication exchange with the server, then Node B performing another full authentication exchange, the patent merges both authentication processes into one message that contains authentication information for both nodes. This reduces the total messaging quantity while maintaining authentication reliability through the integrated verification process.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication message is designed with multi-functionality, serving dual purposes: it provides authentication information for Node A to authenticate Node B, and simultaneously provides authentication information for Node B to authenticate Node A. This universal authentication message eliminates the need for separate authentication messages, reducing messaging overhead while ensuring both nodes are properly authenticated.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication messages are sent for each node authentication, then authentication completeness is improved, but communication efficiency deteriorates

Engineering Contradiction:
Improveauthentication completenessVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges two separate authentication message exchanges into a single integrated authentication message. Rather than Node A sending a complete authentication message to the server, then Node B sending another complete authentication message, the invention combines both authentication requirements into one message structure that the server processes simultaneously, improving communication efficiency while maintaining authentication completeness.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication message is structured to include preliminary authentication information for both nodes before the actual authentication verification. This allows the server to prepare and verify both authentication requests in advance, improving processing efficiency and reducing the overall communication time required for mutual authentication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7676676B2Method and apparatus for performing mutual authentication within a network
Publication Date: 2010.03.09 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US7676676B2 patent drawing
  • US7676676B2 patent drawing
  • US7676676B2 patent drawing

AI summary

A method and apparatus for mutual authentication of a first and a second node is provided herein. During operation the first node sends a first authentication message to the second node comprising information needed for the second node to authenticate the first node and information needed by the second node for the second node to be authenticated by the first node. A second authentication message is received from the second node comprising information needed by the first node for the first node to be authenticated by the second node and information needed for the first node to authenticate the second node. Because the first and the second authentication messages comprise information needed for both the first and the second node to authenticate each other, messaging within the network is greatly reduced.