Network Subscriber Mutual Authentication Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network configuration processes require significant manual effort and complexity to enable access between network subscribers, involving manual information exchange and predefined hard-coded access data, which is inefficient and labor-intensive.

Innovation Solution

An automated method for mutual authentication and authorization of network subscribers, where identification and authentication occur in a first phase, and authorization for secure communication is established in a second phase, eliminating the need for manual configuration and predefined access data, with continuous cyclical identification and secure, encrypted communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration processes are used for network access, then security can be maintained through predefined access data, but the complexity and manual effort required increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables network subscribers to automatically authenticate and authorize themselves without manual configuration. The first network subscriber autonomously transmits identification messages and receives authorization tokens, eliminating the need for manual setup while maintaining security through automated verification processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-registers network subscribers and stores their identification data before actual communication occurs. This preliminary registration phase allows the system to quickly authenticate subscribers during subsequent communications without requiring manual configuration at the time of access

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automated plug-and-play concepts are implemented, then manual effort is reduced, but the need for complex information exchange and authentication protocols increases

Engineering Contradiction:
Improvemanual effortVSAvoidauthentication protocol
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication process is divided into distinct phases: an initial registration phase where subscriber information is stored, and a subsequent communication phase where pre-stored information is used for rapid authentication. This segmentation simplifies the operational complexity while maintaining robust security protocols

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates and stores copies of network subscriber identification data during the registration phase. These stored copies are then used for rapid authentication without requiring repeated complex verification protocols, reducing both manual effort and authentication overhead

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If predefined hard-coded access data are used, then configuration is simplified, but security and flexibility are reduced

Engineering Contradiction:
ImproveconfigurationVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system transitions from static hard-coded access data to dynamic authorization tokens that are generated and updated automatically. The first network subscriber receives authorization tokens that can be updated, revoked, or renewed, providing both ease of configuration and enhanced security with adaptability to changing access requirements

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10924471B2Method for enabling and/or requesting access by a first network subscriber to a second network subscriber in a network
Publication Date: 2021.02.16 ROBERT BOSCH GMBH
  • US10924471B2 patent drawing
  • US10924471B2 patent drawing
  • US10924471B2 patent drawing

AI summary

A method for enabling access by a first network subscriber to a second network subscriber in a network includes receiving a communication request from the first network subscriber and determining whether the second network subscriber has carried out an authentication of the first network subscriber during a first phase. The second network subscriber allows communication with the first network subscriber when the second network subscriber has carried out authentication of the first network subscriber during the first phase. The second network subscriber receives an access request from the first network subscriber and determines a level of trustworthiness of the first network subscriber. The second network subscriber enables access of the first network subscriber based on the determination of the level of trustworthiness of the first network subscriber.