Triple-Unit Access Control Authentication Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network access control methods, particularly the double-unit double-entity and double-unit triple-entity structures, face limitations in flexibility and convenience for managing multiple access controllers, and complicate the process of establishing trust relationships, potentially compromising network security.
Innovation Solution
A peer-to-peer access control method in a triple-unit structure is implemented, where a terminal, an access controller, and a server each have authentication credentials and functions, with the server assisting in authentication between the terminal and access controller, establishing a direct and secure trust relationship.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the double-unit double-entity structure is used for bidirectional authentication, then authentication capability is achieved, but flexibility and ease of managing multiple access controllers are significantly limited
Solution Approach 1:
The patent introduces an authentication server as an intermediary component in the triple-unit structure. The authentication server mediates between multiple access controllers and terminals, centralizing authentication management. This allows multiple access controllers to be managed through a single server, significantly improving flexibility and reducing management complexity compared to the double-unit structure where each access controller must independently authenticate terminals.
2Reliability
If the double-unit triple-entity structure is used with server assistance, then authentication function is enhanced, but the trust relationship establishment process becomes complicated and security may be compromised
Solution Approach 1:
The patent extracts the authentication function from access controllers and concentrates it in the authentication server. In the proposed triple-unit structure, only the authentication server possesses authentication credentials and performs authentication operations. Access controllers are relieved of authentication responsibilities, simplifying the trust relationship establishment process and eliminating the security risks associated with key distribution to multiple access controllers.
3Adaptability or versatility
If multiple access controllers are deployed to serve multiple terminals, then service coverage is improved, but the many-to-many relationship creates management difficulties
Solution Approach 1:
The patent segments the authentication management function from access control functions. The authentication server handles all authentication operations independently, while access controllers focus solely on access control based on authentication results. This segmentation allows multiple access controllers to serve multiple terminals without creating complex many-to-many management relationships, as all authentication is centralized at the server level.
Data Source
AI summary
This invention relates to a peer-to-peer access control method of a triple-unit structure for safely implementing bidirectional authentication between the terminal and the network. According to the method, on the basis of the access control method of the existing double-unit triple-entity structure, the authenticator function is implemented in the access controller, and the authentication protocol function is implemented in the terminal and the access controller, so that the terminal, the access controller and the server all participate in the authentication, and the trust relationship is established between the terminal and the access controller directly, which renders security very reliable. The invention not only solves the technical problems of the access control method of the existing double-unit double-entity structure that the access flexibility is limited and the extension of the number of the access controllers is inconvenient, but also solves the technical problems of the existing access control method of the double-unit triple-entity structure that the process for establishing the trust relationship is complicated and the security of the network may be influenced, thus achieving advantages of high security performance, no requirement of changing existing network structures and relative independency of the authentication protocol.


