Mutual Authentication Network Nodes via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless hotspot authentication protocols, such as WEP and WPA, are vulnerable to attacks and lack mechanisms to verify the authenticity of authentication responses, making it difficult to identify rogue access points and ensuring secure connections.

Innovation Solution

A method for mutual authentication between network nodes that generates and uses identical encryption keys on both the client and server, based on a second token, to securely authenticate and encrypt communication, preventing unauthorized access and ensuring the validity of access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If basic authentication protocols (WEP, WPA) are used, then compatibility with existing wireless equipment is maintained, but security vulnerability increases due to ease of breach

Engineering Contradiction:
ImprovecompatibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the wireless client and access point. This server mediates the authentication process by verifying credentials and providing mutual authentication, thereby enhancing security without requiring changes to the underlying wireless communication protocol, thus maintaining compatibility with existing equipment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct phases: initial connection establishment using existing protocols, followed by a separate mutual authentication phase through the authentication server. This segmentation allows the system to maintain backward compatibility while adding enhanced security capabilities through the authentication server intervention.

Inventive Principle:
Principle #1Segmentation

2Reliability

If advanced authentication protocol (802.1x) is implemented, then security is improved, but hardware and software changes are required causing implementation delay

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server acts as an intermediary that implements the advanced 802.1x authentication logic centrally, allowing individual access points and clients to avoid complex hardware and software modifications. The server handles the cryptographic operations and protocol complexity, making implementation more manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service mutual authentication where the authentication server automatically verifies credentials and establishes secure sessions without requiring manual configuration or intervention, reducing implementation complexity while maintaining advanced security capabilities.

Inventive Principle:
Principle #25Self-service

3Device complexity

If unidirectional authentication is used, then implementation is simpler, but security is compromised as the access point cannot verify the authenticity of authentication responses

Engineering Contradiction:
Improveauthentication mechanism complexityVSAvoidauthentication reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent inverts the traditional authentication model by implementing mutual authentication where both the client and the authentication server verify each other's credentials. This inversion ensures that the access point can verify the authenticity of authentication responses through the server, enhancing reliability while maintaining manageable complexity through the server's central coordination role.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7760882B2Systems and methods for mutual authentication of network nodes
Publication Date: 2010.07.20 JAPAN COMM INC
  • US7760882B2 patent drawing
  • US7760882B2 patent drawing
  • US7760882B2 patent drawing

AI summary

Systems and methods for mutual encryption of network nodes are described. One described method includes transmitting a communication from a client to a server, the communication associated with a credential, the credential having a user identifier and a first token and receiving the communication at the server. The method further includes determining a second token associated with the user identifier on the server and on the client and generating an encryption key based at least in part on the second token on the server and on the client. The method further includes generating and encrypting an encrypted authentication request on the client; transmitting the encrypted authentication request to the server; receiving the encrypted authentication request on the server; decrypting the encrypted authentication request using the encryption key on the server; generating and encrypting an encrypted authentication response on the server; and transmitting the encrypted authentication response to the client.