Mutual Authentication Network Nodes via Intermediary Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless hotspot authentication protocols, such as WEP and WPA, are vulnerable to attacks and lack mechanisms to verify the authenticity of authentication responses, making it difficult to identify rogue access points and ensuring secure connections.
Innovation Solution
A method for mutual authentication between network nodes that generates and uses identical encryption keys on both the client and server, based on a second token, to securely authenticate and encrypt communication, preventing unauthorized access and ensuring the validity of access points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If basic authentication protocols (WEP, WPA) are used, then compatibility with existing wireless equipment is maintained, but security vulnerability increases due to ease of breach
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the wireless client and access point. This server mediates the authentication process by verifying credentials and providing mutual authentication, thereby enhancing security without requiring changes to the underlying wireless communication protocol, thus maintaining compatibility with existing equipment.
Solution Approach 2:
The authentication process is segmented into distinct phases: initial connection establishment using existing protocols, followed by a separate mutual authentication phase through the authentication server. This segmentation allows the system to maintain backward compatibility while adding enhanced security capabilities through the authentication server intervention.
2Reliability
If advanced authentication protocol (802.1x) is implemented, then security is improved, but hardware and software changes are required causing implementation delay
Solution Approach 1:
The authentication server acts as an intermediary that implements the advanced 802.1x authentication logic centrally, allowing individual access points and clients to avoid complex hardware and software modifications. The server handles the cryptographic operations and protocol complexity, making implementation more manageable.
Solution Approach 2:
The system enables self-service mutual authentication where the authentication server automatically verifies credentials and establishes secure sessions without requiring manual configuration or intervention, reducing implementation complexity while maintaining advanced security capabilities.
3Device complexity
If unidirectional authentication is used, then implementation is simpler, but security is compromised as the access point cannot verify the authenticity of authentication responses
Solution Approach 1:
The patent inverts the traditional authentication model by implementing mutual authentication where both the client and the authentication server verify each other's credentials. This inversion ensures that the access point can verify the authenticity of authentication responses through the server, enhancing reliability while maintaining manageable complexity through the server's central coordination role.
Data Source
AI summary
Systems and methods for mutual encryption of network nodes are described. One described method includes transmitting a communication from a client to a server, the communication associated with a credential, the credential having a user identifier and a first token and receiving the communication at the server. The method further includes determining a second token associated with the user identifier on the server and on the client and generating an encryption key based at least in part on the second token on the server and on the client. The method further includes generating and encrypting an encrypted authentication request on the client; transmitting the encrypted authentication request to the server; receiving the encrypted authentication request on the server; decrypting the encrypted authentication request using the encryption key on the server; generating and encrypting an encrypted authentication response on the server; and transmitting the encrypted authentication response to the client.


