Network Authentication via Relay Terminal Correspondence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication technologies lack a method to authenticate terminals accessing a mobile communications network using a relay terminal, which poses challenges in managing network access and ensuring security.

Innovation Solution

An authentication method and device that verify the validity of a terminal accessing a network by using another terminal, through a preset correspondence between terminal types, allowing valid access and storing authentication information for future connections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a terminal accesses the network by using a relay terminal, then terminals without network access functions or with strict electricity consumption requirements can connect to the network, but there is no authentication method to verify the validity of such access

Engineering Contradiction:
Improveterminal access mannerVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a correspondence relationship between the first terminal and second terminal as an intermediary mechanism. The network device verifies the authentication request by checking this pre-established correspondence, enabling authentication of relayed access without requiring the first terminal to directly communicate with the network device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent establishes a correspondence relationship between terminals before the actual network access occurs. This preliminary action of creating and storing the correspondence allows the network device to quickly verify the legitimacy of relayed access requests without complex real-time authentication procedures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the network device directly authenticates every terminal access request, then authentication security is maintained, but the complexity of the authentication procedure increases for relayed access scenarios

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication procedure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The correspondence relationship acts as an intermediary that simplifies the authentication process. Instead of the network device directly managing complex authentication for relayed access, it only needs to verify whether the requested terminal pair exists in the pre-established correspondence, significantly reducing procedural complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a simplified verification mechanism by copying the essential authentication information into a correspondence relationship. The network device only needs to check the existence of this correspondence rather than performing full authentication procedures, reducing complexity while maintaining security.

Inventive Principle:
Principle #26Copying

3Reliability

If the network device stores correspondence information for all terminal pairs, then authentication of relayed access is enabled, but the storage requirements and management complexity increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidstored information
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The correspondence information is established in advance between terminals before network access is needed. This preliminary action allows the network device to store only essential pairing information rather than complete authentication credentials, reducing storage requirements while enabling verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts only the essential correspondence relationship information needed for verification, separating it from complete authentication data. The network device stores and verifies only the pairing correspondence, not the full authentication credentials, minimizing storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3675541B1Authentication method and device
Publication Date: 2023.01.04 HUAWEI TECH CO LTD
  • EP3675541B1 patent drawingFigure 1
  • EP3675541B1 patent drawingFigure 2
  • EP3675541B1 patent drawingFigure 3

AI summary

This application discloses an authentication method and a device. In this method, a first network device receives an authentication request sent by a second network device, where the authentication request includes an identifier of a first terminal and an identifier of a second terminal; the first network device authenticates, based on a preset correspondence between a first-type terminal and a second-type terminal, validity of accessing, by the first terminal, a network by using the second terminal, where a first-type terminal is allowed to access the network by using a second-type terminal corresponding to the first-type terminal; and the first network device sends an authentication response to the second network device, where the authentication response carries indication information used to indicate whether the first terminal is allowed to access the network by using the second terminal. The foregoing method implements authentication on validity of accessing, by the first terminal, the network by using the second terminal, to prevent a case in which a network-side device fails to detect the access of the first terminal when the first terminal accesses the network by using the second terminal.