Network Node Authentication via Vendor Signed Usage Certificate

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating network nodes in communication networks lack efficiency and security, particularly during initial connection, as they either compromise security or require cumbersome pre-configuration and vendor involvement, leaving vulnerabilities to attacker manipulation.

Innovation Solution

A method involving configuring network nodes with a vendor certificate and creating a usage certificate signed by the vendor, which contains verification information, allowing the node to authenticate the operator network securely without pre-configuration, ensuring mutual authentication and preventing attacker manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network nodes are pre-configured with operator certificates for mutual authentication, then security is improved, but device complexity and manufacturing complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vendor creates and signs usage certificates in advance during manufacturing, embedding them in the network node before delivery. This preliminary action eliminates the need for complex post-manufacturing configuration while ensuring security credentials are already in place.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The operator certificate is extracted from the pre-configuration process and replaced with a vendor-signed usage certificate that contains the necessary authentication information. This simplifies the device configuration while maintaining security through the vendor's digital signature verification.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If network nodes are connected without authentication for efficient plug-and-play deployment, then ease of operation and productivity are improved, but reliability and security deteriorate

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidconnection security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The network node automatically performs authentication using the vendor-signed usage certificate already embedded in the device. The node independently verifies the operator network's certificate through the vendor's signature without requiring manual configuration or intervention, achieving both automated deployment and security.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If vendor configures all operator root certificates in network nodes, then adaptability is improved, but device complexity and information security worsen

Engineering Contradiction:
Improveoperator compatibilityVSAvoidcertificate storage complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The vendor acts as an intermediary by signing the usage certificate that contains the operator certificate. The network node only needs to trust the vendor's signature, not individual operator certificates. This single intermediary approach provides universal adaptability while minimizing the certificates stored in each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9762569B2Network authentication
Publication Date: 2017.09.12 NOKIA SOLUTIONS & NETWORKS OY
  • US9762569B2 patent drawing
  • US9762569B2 patent drawing
  • US9762569B2 patent drawing

AI summary

The present invention addresses apparatuses, methods and computer program product for providing improved authentication of a network by a network node. A network node identification and a vendor certificate are configured in a network node, a usage certificate is created for the network node, which is signed by the vendor with a signature, and contains verification information indicating that the usage certificate relates to this network node and authentication information for allowing the network node to authenticate a network, the usage certificate is transmitted to an operator of an operator network, the network node requests the usage certificate from the operator, when the network node is initially connected to the operator network, the network node determines validity of the signature in the usage certificate received upon the request, and the network node checks whether the received usage certificate actually relates to the network node being initially connected to the operator network, based on the information contained in the usage certificate.