Pre-Shared-Key LAN Authentication Protocol for Rapid Bidirectional Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wired local area network (LAN) security access control methods are insecure, as they do not provide user-level security and data confidentiality, and existing authentication protocols like IEEE 802.1x are complex and cannot support rapid identity authentication and bidirectional authentication between terminals and the network.

Innovation Solution

A pre-shared-key-based network security access control method that includes security policy negotiation, identity authentication, and unicast key negotiation between a Requester (REQ) and an Authentication Access Controller (AAC), using a pre-shared-key-based LAN authentication protocol (SAAP) to enable rapid bidirectional authentication and secure key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IEEE 802.1x authentication protocol is used, then network security authentication is improved, but authentication complexity and procedure complexity increase

Engineering Contradiction:
Improvenetwork security authenticationVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines identity authentication and key management functions into a single integrated authentication process. The access point directly performs both authentication and unicast key negotiation with terminals without requiring separate procedures, thereby simplifying the overall authentication流程 while maintaining security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts the authentication server from the authentication process, allowing the access point to independently perform authentication and key management. This removes the complex interaction between multiple entities and simplifies the procedure to a direct peer-to-peer authentication between the access point and terminal.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If authentication server is introduced for security authentication, then authentication reliability is improved, but system complexity and authentication speed deteriorate

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes the authentication server from the system and transfers authentication capabilities to the access point. The access point directly authenticates terminals and performs key management, eliminating the need for a separate authentication server and reducing system complexity while maintaining authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access point performs self-authentication with terminals using pre-shared keys stored locally. Both the access point and terminal have pre-configured authentication credentials, allowing them to authenticate each other directly without external server assistance, thereby simplifying the system architecture.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If direct forwarding of identification information is used, then authentication process simplicity is improved, but bidirectional authentication capability deteriorates

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidbidirectional authentication capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges identity authentication and bidirectional verification into a single integrated process. The access point not only authenticates the terminal's identity but also verifies the terminal's authentication capability simultaneously, achieving both simplicity and bidirectional authentication capability through unified design.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8646055B2Method and system for pre-shared-key-based network security access control
Publication Date: 2014.02.04 CHINA IWNCOMM
  • US8646055B2 patent drawing
  • US8646055B2 patent drawing
  • US8646055B2 patent drawing

AI summary

A method and system for pre-shared-key-based network access control are disclosed. The method includes the following steps: 1) security policy negotiation is implemented between a REQuester (REQ) and Authentication Access Controller (AAC); 2) identity authentication and uni-cast key negotiation are implemented between REQ and AAC; 3) a group-cast key is notified between REQ and AAC. Applying the method and system, rapid bidirectional authentication can be implemented between a user and network.