Two-Step Network Authentication Reducing Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data communication networks face challenges in providing quick and secure authentication, as existing mechanisms like IEEE 802.1X are time-consuming, which can be disastrous in modern security-critical environments.
Innovation Solution
A method that involves a two-step authentication process where the first authentication is performed by an external authentication entity, and the second authentication is performed locally by access nodes using shared information to verify privacy information, allowing faster access to the network without relying on the authentication server, thus reducing latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication mechanisms like IEEE 802.1X are used, then security is improved, but authentication time increases
Solution Approach 1:
The authentication process is divided into two independent phases: a security-critical first authentication with the authentication server, and a time-critical second authentication with the access node. This segmentation allows each phase to be optimized independently for its specific requirements.
Solution Approach 2:
The first authentication is performed in advance before the user needs network access. The authentication server verifies the user's credentials and generates authentication information that is stored and reused for subsequent quick access through access nodes, eliminating the need to contact the server during time-sensitive operations.
2Reliability
If authentication server contact is required for each authentication, then security is maintained, but network latency increases
Solution Approach 1:
The time-consuming server communication step is extracted from the frequent authentication operations. Only the essential security verification is performed with the server during the first authentication, while subsequent authentications use locally cached authentication information to achieve fast access without server contact.
Solution Approach 2:
Authentication information obtained from the server during the first authentication is copied and stored at the access node. This copy enables the second authentication to proceed quickly using local resources without requiring repeated server contact, while still maintaining security through cryptographic verification.
3Speed
If quick access is provided without server contact, then authentication speed is improved, but security may be compromised
Solution Approach 1:
Comprehensive security verification is performed in advance during the first authentication with the server, including credential validation and authentication information generation. This preliminary security action ensures that subsequent quick authentications can rely on pre-verified information without compromising security.
Solution Approach 2:
Authentication information acts as a secure intermediary between the server and the access node. It carries cryptographic evidence of valid authentication, allowing the access node to verify user credentials locally without direct server contact while maintaining security through cryptographic proof.
Data Source
AI summary
The present invention relates to at least a method of authenticating a user in a communication network including contacting an authentication entity in a first authentication of a user seeking access to the communication network; supplying to the user first information, the first information being generated based on privacy information of the user and shared information, the shared information being shared among all access nodes of a group of access nodes, the group of access nodes including at least a first access node and a second access node, and verifying the privacy information in a second authentication of the user by applying the shared information to the first information. The present invention further relates to a corresponding apparatus.


