Split Authentication Network Systems for Certificateless Device Onboarding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional device authentication methods for network access are impractical, dependent on network connection quality, and pose security risks, particularly when using commercial or self-signed certificates.
Innovation Solution
A system comprising an authentication datastore, device presence engine, traffic monitor engine, authentication presence monitor engine, authentication server selection engine, and traffic routing engine that detects user devices on a trusted network, evaluates onboarding characteristics, selects appropriate authentication servers, and routes traffic for secure authentication without requiring device certificates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional device authentication methods are used with commercial or self-signed certificates, then device authentication can be achieved, but security vulnerabilities increase and the process becomes impractical
Solution Approach 1:
The patent extracts the certificate requirement from the authentication process entirely. Instead of requiring devices to have pre-installed commercial or self-signed certificates, the system uses a certificateless authentication mechanism where the authentication server validates devices through other means (such as device identifiers, cryptographic challenges, or trusted hardware modules), thereby eliminating the impracticality of certificate management while maintaining security
Solution Approach 2:
The patent introduces an intermediary authentication server that mediates between devices and the network. This server acts as a trusted third party that can verify device authenticity without requiring direct certificate validation between devices and network access points, simplifying the authentication process and improving practicality
2Reliability
If conventional authentication processes are used, then device authentication can be performed, but the process becomes dependent on network connection quality
Solution Approach 1:
The patent performs preliminary authentication actions that do not require continuous network connectivity. Devices can perform local cryptographic operations, validate local credentials, or establish authentication states before network connection is available, making the authentication process independent of real-time network quality
Solution Approach 2:
The patent enables devices to perform self-validation and self-authentication operations locally without requiring external network verification. Devices can independently verify their own credentials or generate authentication proofs that are later validated by the network, reducing dependency on network connection quality
3Adaptability or versatility
If a single authentication server is used, then the system is simple to manage, but it cannot adapt to different device characteristics and authentication requirements
Solution Approach 1:
The patent segments the authentication server into multiple specialized authentication servers, each optimized for specific device types, authentication protocols, or security requirements. This segmentation allows the system to handle diverse device characteristics effectively while maintaining manageable complexity through modular architecture
Solution Approach 2:
The patent creates authentication servers with multi-functional capabilities that can handle multiple authentication protocols and device types. These universal authentication servers can adapt their behavior based on device characteristics, providing both adaptability and simplified management through a unified multi-purpose platform
Data Source
AI summary
Disclosed is a system comprising: an authentication datastore; a device presence engine; a traffic monitor engine; an authentication presence monitor engine; an authentication server selection engine; and a traffic routing engine. In operation: the device presence engine is configured to detect presence of a user device on a trusted network; the traffic monitor engine is configured to monitor, in response to the detection, traffic on the trusted network from the device; the authentication presence monitor engine is configured to evaluate onboarding characteristics of the user device in response to the monitoring; the authentication server selection engine is configured to select one of a plurality of authentication servers to authenticate the user device to the trusted network, the selecting based on the onboarding characteristics; and the traffic routing engine is configured to route traffic from the user device to the selected authentication server.


