Pre-authentication Filters for Mobile Network Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communication systems face security risks due to stolen or outdated credentials, especially in mobile environments where devices can be easily accessed by unauthorized users, and they lack efficient pre-authentication mechanisms to manage changing access rights.
Innovation Solution
A method and system that establish a service connection between a mobile gateway and a fixed gateway, providing pre-authentication filters to limit communication types, allowing clients to access the ground network securely before full authentication, and enabling communication via entitled types, with credentials requested from a credential server for secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If credentials are stored on mobile devices for network access, then authentication speed is improved, but security is worsened due to theft or unauthorized access
Solution Approach 1:
The system performs preliminary authentication by providing pre-authentication filters to mobile devices before full authentication occurs. These filters enable basic network access and credential verification in advance, so that when the device is stolen or accessed by unauthorized users, the pre-established security filters prevent them from exploiting stored credentials. This resolves the contradiction by preparing security measures beforehand rather than relying solely on stored credentials.
Solution Approach 2:
The patent introduces pre-authentication filters as an intermediary layer between the mobile device and the network. These filters act as a mediator that verifies credentials and controls access before the actual authentication process completes. This intermediary mechanism allows the system to maintain security controls even when credentials are stored on mobile devices, resolving the security-speed contradiction.
2Reliability
If pre-authentication filters are implemented to control access, then security is improved, but device complexity is worsened
Solution Approach 1:
The authentication system is segmented into distinct components: pre-authentication filters, credential servers, and authentication modules. The filters are provided separately to mobile devices and work independently to control access types. This segmentation allows security functionality to be added without requiring complete system redesign, thus improving security while managing complexity through modular architecture.
3Reliability
If full authentication is required before network access, then security is improved, but access speed is worsened
Solution Approach 1:
The system performs preliminary authentication actions by providing pre-authentication filters before full authentication is complete. These filters enable basic network access and credential verification in advance, allowing users to access certain network resources immediately while full authentication proceeds in the background. This resolves the contradiction by providing faster access through preliminary authentication measures.
Solution Approach 2:
The patent implements partial authentication through pre-authentication filters that provide sufficient security for basic network access without requiring complete authentication. This partial action approach allows users to access essential network functions quickly while full authentication occurs separately, balancing security requirements with access speed needs.
Data Source
AI summary
A method and system is disclosed for providing applications and devices in a mobile part access to communications between the mobile part and a fixed part and such that prior to completion of authentication of the mobile part with the fixed part certain types of communications between the mobile part and the fixed part are supported by a service connection not requiring completion of authentication. The types of communications able to use the service connection are provided to the mobile part in the form of a pre-authentication filter.


