Relay Node Aggregation to Reduce Network Authentication Load

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication processes in IoT devices result in heavy network load due to numerous interactions required for session key generation, leading to increased overheads and congestion.

Innovation Solution

A network authentication method involving a relay node that aggregates authentication messages from multiple user equipments, generating an aggregated signature or authentication code, and sends it to a cellular network authentication element, reducing the need for individual message verification and minimizing data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional individual authentication is used for each user equipment, then authentication security is maintained, but network load and data overheads increase significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple individual authentication requests into a single group authentication request. The network side aggregates authentication vectors from multiple user equipments and performs batch verification, reducing the number of separate authentication interactions while maintaining security through cryptographic aggregation techniques.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is enhanced to support both individual authentication and group authentication modes. The network side can selectively apply aggregation based on the authentication scenario, making the system versatile for different load conditions and security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If numerous user equipments perform network authentication simultaneously, then network coverage and service capacity are improved, but authentication overhead and network congestion worsen

Engineering Contradiction:
Improvenetwork coverageVSAvoidauthentication overhead
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network side performs preliminary aggregation of authentication vectors before actual authentication verification. By pre-processing and batching authentication data from multiple user equipments, the system reduces the complexity of simultaneous individual verifications and minimizes network congestion during peak authentication periods.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If individual authentication interactions are performed for each user equipment, then authentication accuracy is ensured, but signaling traffic and network congestion increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsignaling traffic
Core Design Contradiction:
Measurement precisionVSLoss of substance

Solution Approach 1:

Multiple individual authentication signaling interactions are merged into a single group authentication signaling exchange. The network side aggregates authentication vectors and performs batch verification, significantly reducing the total signaling traffic while maintaining authentication accuracy through cryptographic aggregation that preserves individual authentication integrity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3461061B1Network authentication method, relay node and relative system
Publication Date: 2025.07.30 HUAWEI TECH CO LTD
  • EP3461061B1 patent drawingFigure 1
  • EP3461061B1 patent drawingFigure 2
  • EP3461061B1 patent drawingFigure 3A-1

AI summary

Embodiments of the present invention disclose a network authentication method, a relay node, and a related system. The system includes user equipment, a relay node, and a cellular network authentication network element. The user equipment is configured to send a first authentication message to the relay node; the relay node is configured to receive first authentication messages sent by a plurality of user equipments, and generate first encrypted information by using an aggregation algorithm based on first encrypted identifiers in the first authentication messages sent by the plurality of user equipments; the cellular network authentication network element is configured to receive a first aggregation message, and when verifying, by using the first encrypted information, that information in the first aggregation message is correct, send a first response message to the relay node; and the user equipment is configured to generate a session key between the user equipment and the cellular network authentication network element when verifying that information in the first response message is correct and carries a first verification identifier of the user equipment. According to the embodiments of the present invention, load of an authentication network element on a network side can be alleviated when a plurality of user equipments perform network authentication.