Network Authentication Binding User and Platform Identities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing trusted network connection authentication processes for mobile terminals, user identity authentication and platform identity authentication are independent, allowing attackers to simulate user identity information from another authorized terminal, posing a potential network security risk.

Innovation Solution

The authentication server obtains and compares second and third authentication information during user and platform identity authentication stages to ensure consistency, preventing attackers from accessing the network by simulating user identity information, thereby binding user and platform identity authentication processes together.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user identity authentication and platform identity authentication are performed as independent processes, then authentication simplicity is improved, but network security deteriorates

Engineering Contradiction:
Improveauthentication simplicityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges user identity authentication and platform identity authentication into a unified authentication process. The authentication server performs both user authentication and platform authentication simultaneously, and binds the user identity and platform identity through association relationships, ensuring that both identities are verified together rather than independently. This resolves the security vulnerability where attackers could use stolen user credentials with unrelated platform information.

Inventive Principle:
Principle #5Merging (Combining)

2Device complexity

If user identity and platform identity are not associated, then authentication process complexity is reduced, but security risk increases

Engineering Contradiction:
Improveauthentication process complexityVSAvoidsecurity risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the authentication server verifies the association relationship between user identity and platform identity during the authentication process. The server checks whether the platform identity presented by the terminal corresponds to the authenticated user identity, and only grants network access when the association is confirmed. This feedback loop ensures security without significantly increasing process complexity.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If separate authentication processes are used for user identity and platform identity, then authentication flexibility is improved, but vulnerability to simulation attacks worsens

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidvulnerability to simulation attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing the association relationship between user identity and platform identity before the actual authentication occurs. The authentication server pre-records the binding between user credentials and platform information, then uses this pre-established relationship to verify during authentication that the presented platform identity matches the authenticated user identity. This prevents simulation attacks where attackers use stolen user credentials with unrelated platform information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3694243B1Method and system for network connection authentication
Publication Date: 2023.06.21 HUAWEI TECH CO LTD
  • EP3694243B1 patent drawingFigure 1
  • EP3694243B1 patent drawingFigure 2
  • EP3694243B1 patent drawingFigure 3

AI summary

A method and an apparatus for authenticating network access of a terminal are provided. The method includes: sending, by the terminal, a user identity authentication request including first authentication information and second authentication information to an authentication server, where the first authentication information is used to authenticate a user identity of the terminal, and the second authentication information is used to determine a platform corresponding to the terminal; and after receiving user identity authentication acknowledgment information sent by the authentication server, sending, by the terminal to the authentication server, a platform identity authentication request including third authentication information used to determine the platform corresponding to the terminal. The authentication server sends platform identity authentication acknowledgment information to the terminal only when determining that the platform corresponding to the second authentication information is consistent with the platform corresponding to the third authentication information. Therefore, in a trusted network connection authentication process, an attacker can be prevented from attacking a network by simulating user identity information of another authorized terminal at a platform identity authentication stage, thereby avoiding a potential network security risk.