Triple-Unit Access Control Authentication Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control methods, particularly the double-unit double-entity and double-unit triple-entity structures, face limitations in flexibility and convenience for managing multiple access controllers, and complicate the process of establishing trust relationships, potentially compromising network security.

Innovation Solution

A peer-to-peer access control method in a triple-unit structure is implemented, where a terminal, an access controller, and a server each have authentication credentials and functions, with the server assisting in authentication between the terminal and access controller, establishing a direct and secure trust relationship.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the double-unit double-entity structure is used for bidirectional authentication, then authentication capability is achieved, but flexibility and ease of managing multiple access controllers are significantly limited

Engineering Contradiction:
ImproveflexibilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary component in the triple-unit structure. The authentication server mediates between multiple access controllers and terminals, centralizing authentication management. This allows multiple access controllers to be managed through a single server, significantly improving flexibility and reducing management complexity compared to the double-unit structure where each access controller must independently authenticate terminals.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the double-unit triple-entity structure is used with server assistance, then authentication function is enhanced, but the trust relationship establishment process becomes complicated and security may be compromised

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtrust relationship complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from access controllers and concentrates it in the authentication server. In the proposed triple-unit structure, only the authentication server possesses authentication credentials and performs authentication operations. Access controllers are relieved of authentication responsibilities, simplifying the trust relationship establishment process and eliminating the security risks associated with key distribution to multiple access controllers.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If multiple access controllers are deployed to serve multiple terminals, then service coverage is improved, but the many-to-many relationship creates management difficulties

Engineering Contradiction:
Improveservice coverageVSAvoidmanagement convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the authentication management function from access control functions. The authentication server handles all authentication operations independently, while access controllers focus solely on access control based on authentication results. This segmentation allows multiple access controllers to serve multiple terminals without creating complex many-to-many management relationships, as all authentication is centralized at the server level.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8495712B2Peer-to-peer access control method of triple unit structure
Publication Date: 2013.07.23 CHINA IWNCOMM
  • US8495712B2 patent drawing
  • US8495712B2 patent drawing
  • US8495712B2 patent drawing

AI summary

This invention relates to a peer-to-peer access control method of a triple-unit structure for safely implementing bidirectional authentication between the terminal and the network. According to the method, on the basis of the access control method of the existing double-unit triple-entity structure, the authenticator function is implemented in the access controller, and the authentication protocol function is implemented in the terminal and the access controller, so that the terminal, the access controller and the server all participate in the authentication, and the trust relationship is established between the terminal and the access controller directly, which renders security very reliable. The invention not only solves the technical problems of the access control method of the existing double-unit double-entity structure that the access flexibility is limited and the extension of the number of the access controllers is inconvenient, but also solves the technical problems of the existing access control method of the double-unit triple-entity structure that the process for establishing the trust relationship is complicated and the security of the network may be influenced, thus achieving advantages of high security performance, no requirement of changing existing network structures and relative independency of the authentication protocol.