Single Authentication Sequence for Multi-Session AAA Server Load Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on systems require multiple authentication exchanges across a network, leading to increased load on AAA servers and redundant authentication processes, especially in wireless contexts where access points need to authenticate with multiple applications.

Innovation Solution

A system and method that allow a device to complete a single authentication sequence with a AAA server, enabling multiple secure sessions with different applications or subsystems by generating session keys and allowing additional subsystems to operate securely without full authentication exchanges, thus reducing AAA server traffic and message count.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication exchanges are performed for different applications, then each application can be securely authenticated, but the load on AAA servers increases significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidAAA server load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent combines multiple authentication exchanges into a single authentication sequence. The supplicant performs one authentication with the AAA server, and the server uses the resulting session key to establish multiple secure sessions with different applications simultaneously, eliminating redundant authentication steps

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The single authentication session serves multiple functions by enabling the supplicant to access multiple different applications. The session key obtained from the first authentication is reused to establish secure sessions with various applications, making the authentication process universal across multiple services

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication exchanges are performed for different applications, then each application can be securely authenticated, but the number of network messages increases

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple authentication message exchanges into a single authentication sequence. Instead of performing separate authentication handshakes for each application, the system performs one authentication exchange that results in multiple secure sessions, significantly reducing network traffic

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary authentication once to obtain a session key, which is then used to establish multiple subsequent secure sessions with different applications. This preliminary action eliminates the need for repeated authentication messages for each application

Inventive Principle:
Principle #10Preliminary action

3Productivity

If a single authentication sequence is performed, then AAA server load is reduced, but multiple secure sessions must be established without additional authentication

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidsession management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a session key as an intermediary that bridges the single authentication and multiple secure sessions. The session key obtained from the initial authentication serves as the mediator that enables establishment of multiple secure sessions with different applications without requiring additional authentication exchanges

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs the preliminary authentication action once to obtain a session key, which is then used to establish multiple subsequent secure sessions. This preliminary action simplifies the overall process by performing authentication only once while enabling multiple sessions

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7562224B2System and method for multi-session establishment for a single device
Publication Date: 2009.07.14 CISCO TECHNOLOGY INC
  • US7562224B2 patent drawing
  • US7562224B2 patent drawing
  • US7562224B2 patent drawing

AI summary

A system and method that allows a device to complete a single complete authentication sequence to a AAA server resulting in as many secure sessions required for the different applications or subsystems determined by the client's identity and the AAA server's policy. As the device is authenticated, it is determined where there are other sessions for the device. The sessions are established by generating unique new keying material that is passed to each session. This can be accomplished by (a) the authenticator or AAA server issuing the keys and distributing them to both the supplicant and applications (via their authenticators); or (b) authenticator or the AAA server mutually generating the session unique keys with the supplicant that are then distributed to the applications (via their authenticators).