Radio Authentication Root of Trust for TLS Network Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Converged wireless communication devices face challenges in establishing secure IP-based communication due to the risk of man-in-the-middle (MITM) attacks when switching from LMR to IP-based networks, and distributing root certificates to a fleet of devices is laborious.

Innovation Solution

The solution involves using pre-existing LMR authentication as a root of trust for IP-based communication, where the device establishes a secure IP session with a proxy server, computes authentication challenges based on received certificates, and verifies authentication results using hash functions and shared keys without relying on pre-shared certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If root certificates are distributed to devices for secure IP-based communication, then security against MITM attacks is improved, but device provisioning complexity and time increase

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses the LMR network as an intermediary trust anchor. Instead of directly distributing root certificates for IP-based communication, the system leverages the existing LMR authentication infrastructure (which devices already possess) as a mediator to establish trust for the IP-based TLS connection. The LMR network acts as a trusted third party that enables the device to verify the proxy server's certificate without requiring pre-distributed root certificates for the IP network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the LMR authentication infrastructure serve multiple functions: it continues to provide traditional LMR network access while simultaneously serving as a root of trust for IP-based communication. The same authentication credentials and infrastructure used for LMR network access are reused to establish trust for TLS-protected IP sessions, eliminating the need for separate certificate distribution mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional authentication methods are used for IP-based communication, then security is maintained, but the authentication process becomes laborious and time-consuming

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary authentication through the LMR network before establishing IP-based communication. Since devices must already be authenticated to the LMR network to obtain access credentials, this preliminary LMR authentication serves as a pre-established trust relationship. When the device later needs to establish a TLS connection for IP-based communication, it can reuse this pre-established trust anchor (the LMR network's certificate authority) to quickly verify the proxy server's certificate without undergoing a separate, time-consuming certificate verification process.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If converged devices switch between LMR and IP-based networks, then communication flexibility is improved, but vulnerability to MITM attacks increases

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidMITM attack risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses the LMR network infrastructure as a trusted intermediary that bridges the two communication modalities. When switching from LMR to IP-based networks, the device maintains security by using the LMR network's established trust relationship to verify the identity of the proxy server mediating the IP connection. This intermediary trust anchor ensures that even during network switching, the device can authenticate the proxy server and prevent MITM attacks, as the LMR network's certificate authority serves as a reliable mediator that both the device and proxy server trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4654528A1Radio authentication as root of trust for transport layer security
Publication Date: 2025.11.26 MOTOROLA SOLUTIONS INC
  • EP4654528A1 patent drawingFigure 1~2
  • EP4654528A1 patent drawingFigure 3
  • EP4654528A1 patent drawingFigure 4

AI summary

A converged radio device (MS) is configured to perform communication in an internet protocol (IP) based network and authenticate with a switching and management infrastructure (SwMI) of a second network by using pre-existing radio authentication as a root of trust for an unauthenticated IP session established between the MS and a server associated with the SwMI. The MS receives a first challenge from the SwMI via the server, and determines a result of the first challenge using data derived from a certificate associated with the server. The MS transmits, to the SwMI via the server, a second challenge and the result of the first challenge. The MS authenticates the SwMI by verifying a result of the second challenge received from the SwMI via the server matches an expected result of the second challenge. Responsive to a mutual authentication, the MS performs communication in the radio network via the server.