Neighbor AP Authentication for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network authentication procedures for access points (APs) are vulnerable to attacks, as malicious APs can join the network using stolen certifications, compromising network security.

Innovation Solution

Implementing a neighbor authentication procedure where an AP requesting to join the network must also obtain an authentication code from a verified neighbor AP, providing a secondary layer of authentication before being accepted into the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication procedure is used, then the authentication process is simple and fast, but the network security is compromised as malicious APs can join using stolen certifications

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a neighbor AP as an intermediary authentication authority. Instead of relying solely on the controller, the authentication process involves a third-party neighbor AP that generates authentication codes. This intermediary layer prevents malicious APs from joining even with stolen certifications, as the neighbor AP independently verifies legitimacy before issuing authentication codes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary verification by the neighbor AP before the target AP joins the network. The neighbor AP pre-generates authentication codes and verifies the legitimacy of the target AP in advance. This preliminary action ensures that only authenticated APs receive valid authentication codes, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If neighbor authentication procedure is implemented, then the network security is enhanced, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The neighbor AP performs authentication verification in advance before the target AP needs to join the network. By pre-generating authentication codes and verifying legitimacy beforehand, the system reduces the time required during the actual authentication process. The preliminary action ensures that when authentication is needed, the process is faster since verification has already occurred.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11805415B2Authentication enhancement with neighbor device
Publication Date: 2023.10.31 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11805415B2 patent drawing
  • US11805415B2 patent drawing
  • US11805415B2 patent drawing

AI summary

In embodiments of the present disclosure, there is provided a method for authenticating an access point. In the method, a request for joining a network is received from an access point. A neighbor authentication notification is transmitted to the access point for obtaining an authentication code from a neighbor access point that is connected in the network in accordance with a determination that the access point is verified. The authentication code that is generated by the neighbor access point is received from the access point. The access point is accepted to join the network in accordance with a determination that the authentication code is valid. Embodiments of the present disclosure present a safe and effective way for authenticating the access point that is requesting to join the network, which provides enhanced authentication and increases the security level of the network.