Network Node Authentication Using Position Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in industrial control systems are time-consuming and costly, especially for devices with constrained resources, and often compromise communication security due to the need for complex encryption and digital certificates.

Innovation Solution

An authentication method and apparatus that uses position information to authenticate network nodes, leveraging a simple and flexible approach suitable for industrial control fields, which reduces deployment costs and power consumption by utilizing a positioning server to determine the location of network nodes for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex encryption means and digital certificates are used for authentication, then communication security is improved, but system response capability and operation efficiency deteriorate

Engineering Contradiction:
Improvecommunication securityVSAvoidsystem response capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the authentication process from complex encryption protocols and digital certificate verification, isolating only the essential security verification step. The server obtains position information from a positioning server and performs simple location-based authentication, eliminating the need for complex cryptographic operations while maintaining security for constrained devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces expensive, computationally intensive digital certificates with a simple, lightweight position information verification mechanism. This disposable-like approach uses minimal computational resources and can be quickly executed, suitable for devices with constrained processing capabilities that cannot sustain complex security protocols.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If complex encryption means are deployed to improve security, then communication security is improved, but deployment costs and system complexity increase

Engineering Contradiction:
Improvecommunication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts authentication from complex encryption protocols, using only position information verification. This simplifies the system architecture by removing the need for certificate management, key distribution, and cryptographic library integration, reducing both deployment complexity and operational overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical system of complex cryptographic operations with a simpler information-based verification mechanism. Instead of performing computationally intensive encryption and decryption operations, the system uses position information comparison, which requires minimal processing power and simplifies the overall system design.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If manual digital certificate installation is performed for clients, then authentication capability is improved, but installation time and operational complexity increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent enables devices to perform self-authentication using position information obtained from a positioning server. Devices automatically obtain their position information and present it for verification without requiring manual certificate installation or configuration, eliminating time-consuming setup procedures and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication setup by having devices automatically obtain position information from a positioning server before actual authentication is needed. This preliminary action eliminates the need for manual certificate installation, as the position information is readily available and can be used immediately for authentication purposes.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If position information-based authentication is used, then system response capability and deployment cost are improved, but authentication complexity increases

Engineering Contradiction:
Improvesystem response capabilityVSAvoidauthentication complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a positioning server as an intermediary that provides position information to both clients and servers. This mediator simplifies the authentication process by centralizing position information management, eliminating the need for devices to implement complex authentication logic, and reducing overall system complexity while improving response capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12075240B2Authentication method and apparatus
Publication Date: 2024.08.27 SIEMENS AG
  • US12075240B2 patent drawing
  • US12075240B2 patent drawing

AI summary

An authentication method and apparatus are provided. In an embodiment, the authentication method includes: receiving, by a first network node, an enrollment request from a second network node; obtaining, by the first network node, position information of the second network node; and authenticating, by the first network node, the second network node according to the obtained position information of the second network node. A flexible simple authentication solution is provided, having low deployment costs.