Subscriber Station Security Parameter Negotiation in Wireless Internet
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The conventional wireless portable Internet system lacks the ability to efficiently support various authentication schemes and message authentication codes, limiting system performance and provider policy flexibility in authentication function management.
Innovation Solution
A subscriber station security-related parameter negotiation method that includes transmitting and receiving basic capability negotiation messages with security negotiation parameters, allowing for the selection and omission of authentication functions and message authentication codes, supporting multiple authentication modes and protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If only RSA-based or EAP-based authentication scheme is supported, then the system maintains simplicity in authentication implementation, but the system lacks versatility in supporting various authentication schemes and cannot omit authentication functions according to provider policy
Solution Approach 1:
The patent implements a universal authentication negotiation mechanism where the subscriber station and base station exchange capability information through SBC-REQ and SBC-RSP messages. The system supports multiple authentication schemes (RSA, EAP, and other schemes) by allowing both parties to indicate their supported schemes in the negotiation process, enabling the system to adapt to different authentication requirements without requiring separate implementation for each scheme.
Solution Approach 2:
The patent introduces dynamic authentication scheme selection through capability negotiation. Instead of statically supporting only one authentication scheme, the system dynamically determines the authentication method to be used based on the capabilities advertised by the subscriber station and the base station's policy. This allows the authentication function to be enabled or omitted based on provider policy and system requirements.
2Reliability
If authentication function is mandatory, then security is ensured, but system performance is reduced and provider policy flexibility is limited
Solution Approach 1:
The patent enables dynamic control of the authentication function through capability negotiation. The base station can determine whether to perform authentication based on provider policy and system conditions. When authentication is omitted, system performance is enhanced as the authentication overhead is removed. This dynamic approach allows the system to balance security requirements with performance needs according to specific operational contexts.
3Reliability
If message authentication function is always performed, then message integrity is protected, but system overhead increases and flexibility in selecting authentication schemes is reduced
Solution Approach 1:
The patent implements dynamic message authentication through capability negotiation. The subscriber station indicates its supported message authentication schemes (HMAC, CMAC, etc.) in the SBC-REQ message, and the base station selects the appropriate scheme based on policy and system requirements. The message authentication function can be enabled or omitted depending on the negotiated capabilities and provider policy, allowing the system to balance message integrity protection with overhead reduction.
Data Source
AI summary
The present invention relates to a subscriber station security-related parameter negotiation method in a wireless portable Internet system. The subscriber station security-related parameter negotiation method includes security-related parameters in transmitting/receiving basic capability negotiation request messages and basic capability negotiation response messages such that the subscriber station and the base station negotiate the subscriber station security-related parameters. The security-related parameters include an authorization policy support subfield used to negotiate an authorization policy between the subscriber station and the base station, and message authentication code mode subfields used to negotiate a message authentication code mode. The base station can inform the subscriber station that authentication or message authentication is not performed and is omitted according to a service provider policy by writing it on the authorization policy support subfield or message authentication code mode subfield. In addition, the subscriber station and the base station can select an authorization policy formed with at least one combination through the authorization policy support subfield of the security negotiation parameters. According to the present invention, the service provider of the wireless portable Internet system can more efficiently and flexibly manage the system by providing a scheme for omitting an authentication function and a message authentication function as well as for supporting various authorization policies and message authentication functions.


