Static User Terminal Authentication via EAP Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for static user terminals in broadband networks lack security and mobility, particularly in wireless LAN scenarios, where circuit authentication is complex and insecure, leading to difficulties in air interface data security and limited user mobility.

Innovation Solution

Implementing an Extensible Authentication Protocol (EAP) authentication method for static user terminals, which involves sending an identity request message, receiving a response, and performing EAP authentication, followed by negotiating a key for air interface data message interaction using a pair-wise master key, and interacting with an AAA server for secure network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If circuit authentication is used for static user terminals, then user identity can be verified, but security is poor and mobility is limited

Engineering Contradiction:
Improveauthentication securityVSAvoiduser mobility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the authentication parameter from circuit-based identification to certificate-based cryptographic verification. By transforming the authentication mechanism from checking circuit parameters (MAC address, IP address) to verifying digital certificates and cryptographic signatures, the system achieves both high security and user mobility without being bound to specific circuit configurations.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If manual network configuration is used for static users, then network parameters can be set, but maintenance complexity increases

Engineering Contradiction:
Improvenetwork configurationVSAvoidmaintenance complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where user terminals automatically perform certificate verification and authentication procedures without requiring manual configuration of network parameters. The terminal autonomously manages its own authentication credentials and completes the verification process with the network device, eliminating the need for operators to manually configure MAC addresses, IP addresses, and other network parameters.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional authentication methods are used, then static users can access network, but air interface data security cannot be ensured

Engineering Contradiction:
Improvedata securityVSAvoidauthentication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces cryptographic certificates and cryptographic verification mechanisms as intermediaries between the user terminal and the network. Instead of direct trust relationships, the system uses digitally signed certificates as mediators that provide cryptographic proof of identity and authorization, ensuring air interface data security through mathematical verification rather than simple parameter matching.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9948647B2Method and device for authenticating static user terminal
Publication Date: 2018.04.17 ZTE CORP
  • US9948647B2 patent drawing
  • US9948647B2 patent drawing
  • US9948647B2 patent drawing

AI summary

Provided are a method and device for authenticating a static user terminal. The method comprises: an identity request message used for acquiring a user identity of the static user terminal is sent to the static user terminal; a response message is received from the static user terminal, wherein the response message carries the user identity of the static user terminal; and, an Extensible Authentication Protocol (EAP) authentication is performed on the static user terminal according to the user identity of the static user terminal. The present disclosure solves the problem in the related art of low security in the authentication on the static user terminal access the network, thus achieving the effects of increasing the security and reliability in the authentication on the static user terminal accessing the network and improving the WLAN service using experience of the static user.