Node Authentication via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems lack a method for authenticating between nodes, leading to security issues during information transmission and reception, as existing authentication procedures only facilitate authentication between a node and a Network Access Server, not between nodes themselves.

Innovation Solution

A method and apparatus for authenticating nodes in a communication system, where nodes registered to different authentication servers perform mutual authentication through their respective servers using Identifier (ID) and authentication codes, generating a security key for encrypted communication, ensuring secure data exchange between nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing authentication procedures are used, then authentication between node and Network Access Server is achieved, but authentication between nodes themselves cannot be performed

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary that enables nodes to authenticate each other. The authentication server acts as a mediator that receives authentication requests from nodes, verifies their credentials, and issues authentication tokens. This allows nodes to perform mutual authentication without direct peer-to-peer verification, resolving the limitation of existing node-to-NAS authentication procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server is designed to serve multiple functions: it authenticates nodes to the network, enables mutual authentication between nodes, and provides security services for data transmission. This multi-functional approach extends the authentication capability beyond traditional node-NAS authentication to include node-node authentication, thereby improving versatility while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If no authentication method between nodes is implemented, then system complexity is reduced, but security during information transmission deteriorates

Engineering Contradiction:
Improveauthentication systemVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

By introducing an authentication server as an intermediary, the patent avoids the complexity of implementing direct peer-to-peer authentication algorithms in each node. Instead, authentication logic is centralized in the server, which simplifies the nodes while providing robust security. The server handles credential verification and token issuance, eliminating security vulnerabilities associated with unauthenticated node communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication server performs preliminary authentication actions before allowing node communication. Nodes must first authenticate with the server and receive authentication tokens before they can communicate with each other. This preliminary authentication step prevents unauthorized nodes from participating in the network, addressing security vulnerabilities without requiring complex continuous verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication between nodes is enabled, then data transmission security is improved, but authentication procedure complexity increases

Engineering Contradiction:
Improvedata transmission securityVSAvoidauthentication procedure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server acts as a mediator that simplifies the authentication procedure for nodes. Instead of nodes implementing complex mutual authentication algorithms, they simply send their identifiers to the server, which performs the authentication logic and returns tokens. This intermediary approach improves data transmission security while keeping the authentication procedure simple for nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses authentication tokens as copies or representations of authenticated nodes. These tokens contain encoded authentication information that allows nodes to prove their identity without transmitting sensitive credentials. The tokens serve as simplified copies of authentication state, enabling secure communication while reducing the complexity of authentication procedures.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9306748B2Authentication method and apparatus in a communication system
Publication Date: 2016.04.05 SAMSUNG ELECTRONICS CO LTD
  • US9306748B2 patent drawing
  • US9306748B2 patent drawing
  • US9306748B2 patent drawing

AI summary

An authentication method and apparatus in a communication system are provided. In a method for authenticating a first node at a second authentication server in a communication system comprising the first node registered to a first authentication server and a second node registered to the second authentication server, an authentication request message requesting authentication of the first node is received from the second node, the authentication request message is transmitted to the first authentication server, and upon receipt of an authentication success message indicating successful authentication of the first node from the first authentication server, the authentication success message is transmitted to the second node.