Security Anchor Equipment for EAP Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication network authentication methods, such as those using Extensible Authentication Protocol (EAP), are vulnerable to denial of service (DOS) attacks and may not ensure fresh authentication due to insufficient randomness.

Innovation Solution

The introduction of security anchor equipment that relays EAP messages and authenticates communication devices, generating random tokens to enhance authentication freshness and protect against overload attacks by verifying responses in the serving network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the home network uses EAP to authenticate communication devices, then authentication can be performed, but the EAP server becomes vulnerable to denial of service attacks and overload

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidDOS attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security anchor equipment as an intermediary component between the communication device and the EAP server. This security anchor equipment performs preliminary authentication checks and message validation before EAP messages reach the EAP server, thereby protecting the server from direct exposure to authentication requests and potential DOS attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security anchor equipment performs preliminary authentication actions by validating authentication requests and messages before they are forwarded to the EAP server. This preliminary action filters out malicious or invalid requests, preventing them from overloading the EAP server while still allowing legitimate authentication to proceed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the home network uses EAP for authentication, then authentication can be performed, but the authentication process may not ensure freshness due to insufficient randomness

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication freshness
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent enhances the randomness parameter in the authentication process by introducing additional random elements generated by the security anchor equipment. This modifies the authentication parameters to include extra entropy, ensuring that each authentication instance is unique and fresh, thereby preventing replay attacks and ensuring authentication integrity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security anchor equipment authenticates communication devices in the serving network, then authentication reliability improves and DOS attacks are protected against, but device complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security anchor equipment is designed to perform multiple functions: it relays EAP messages between communication devices and the EAP server, authenticates devices independently, generates random tokens for freshness, and protects against DOS attacks. By consolidating these multiple functions into a single component, the patent avoids proportionally increasing network complexity while achieving improved reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240276215A1Serving Network Authentication of a Communication Device
Publication Date: 2024.08.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240276215A1 patent drawing
  • US20240276215A1 patent drawing
  • US20240276215A1 patent drawing

AI summary

Security anchor equipment (20) relays Extensible Authentication Protocol, EAP, messages (12M) between a communication device (10) and an authentication server (30) that is operating as an EAP server for an EAP Authentication and Key Agreement, AKA, procedure (12) between the communication device (10) and the authentication server (30). The security anchor equipment (20) receives, from the communication device (10), a response (16) to a challenge (14). The security anchor equipment (20) checks whether the response (16) corresponds to an expected response (18) as part of an attempt by the security anchor equipment (20) to authenticate the communication device (10). In some embodiments, at least one of the response (16), the challenge (14), and the expected response (18) is, or is derived using, information used in the EAP AKA procedure (12) between the communication device (10) and the authentication server (30).