Network Trust List Generation via Authentication Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In open front haul networks, there is no mechanism for a single network entity to have a comprehensive view of all authenticated network entities, leading to a lack of explicit trust levels and potential network disruptions due to the local storage of authentication information and assumption of trust based on connection rather than explicit verification.

Innovation Solution

A system and method that create and share authentication lists between network entities to generate trust lists, specifying trust levels between entities, enabling a centralized view of authenticated supplicants and explicit trust definitions across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If authentication information is kept locally within network entities, then each entity can maintain its own authentication state, but no single network entity can have a comprehensive view of all authenticated network entities

Engineering Contradiction:
Improvecomprehensive view of authenticated network entitiesVSAvoidauthentication information management
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges authentication information from multiple network entities into a centralized authentication information store. The trust relationship manager collects authentication information from different network entities and consolidates it into a single comprehensive view, allowing any network entity to access complete authentication data without maintaining complex local copies.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If network entities are assumed to be trustworthy based on connection to authenticated entities, then trust can be established quickly, but there is no explicit verification of trust levels

Engineering Contradiction:
Improvetrust verificationVSAvoidtrust establishment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary authentication verification by maintaining an up-to-date authentication information store that contains verified authentication data before trust relationships are established. The trust relationship manager checks this pre-verified information against the target network entity's authentication status, enabling fast and reliable trust establishment without repeated verification overhead.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If authentication information is distributed locally across network entities, then each entity can independently verify its direct authentication state, but there is no mechanism to share authentication information with entities not directly involved in authentication

Engineering Contradiction:
Improveauthentication information sharingVSAvoidauthentication visibility
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent introduces a trust relationship manager as an intermediary that mediates authentication information sharing between network entities. This manager maintains a centralized authentication information store and provides controlled access to authentication data, allowing any network entity to verify the authentication status of any other entity without requiring direct involvement in the original authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250007916A1System and method for advertising supplicants in a network
Publication Date: 2025.01.02 RAKUTEN SYMPHONY INC
  • US20250007916A1 patent drawing
  • US20250007916A1 patent drawing
  • US20250007916A1 patent drawing

AI summary

Provided are system, method, and device for enabling network entities to view authenticated supplicants in a network. According to embodiments, the system may include: a memory storage storing computer-executable instructions; and at least one processor communicatively coupled to the memory storage, wherein the at least one processor may be configured to execute the instructions to: create a first authentication list for a first network entity; receive a second authentication list from a second network entity; and create a trust list for the first network entity based on the first authentication list and the second authentication list, wherein the trust list for the first network entity specifies a trust level between the first network entity and one or more network entities in the first and second authentication lists.