Unified Authentication Token for Trunking System Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing trunking systems face security threats due to the need for multiple authentication authorizations for user accounts and private voice calls, with user names and passwords being saved separately, which complicates security management.

Innovation Solution

A unified authentication method using a User ID as a unified identifier for application services, where a token is assigned by an authorization authentication network element to a user upon logon, allowing for combined authentication authorization across multiple application services, enhancing security by simplifying the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication authorizations are performed separately for user accounts and application services, then security coverage is improved, but device complexity and information security risk increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate authentication authorizations (user account authentication and application service authentication) into a unified authentication process. The authentication authorization server integrates both authentication functions, allowing the terminal to perform a single authentication that validates both the user account and application service access, thereby reducing authentication complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication authorization server is designed to perform multiple authentication functions universally. It handles both user account verification and application service access control through a single authentication mechanism, eliminating the need for separate authentication systems and reducing the overall complexity of the authentication architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If user names and passwords are saved separately for different authentication authorizations, then authentication coverage is improved, but information security risk increases

Engineering Contradiction:
Improveauthentication coverageVSAvoidinformation security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges the storage and management of user names and passwords into a unified authentication authorization server. Instead of maintaining separate credentials for different authentication types, the system consolidates all authentication data in one secure location, reducing the attack surface and eliminating the security risks associated with multiple separate credential stores.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts the credential storage function from multiple distributed locations and consolidates it into a single authentication authorization server. This centralization removes the vulnerability of having multiple separate password files that could be individually compromised, thereby reducing information security risks while maintaining comprehensive authentication coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If unified authentication is implemented using token and User ID, then information security is improved, but ease of operation may be affected

Engineering Contradiction:
Improveinformation securityVSAvoidauthentication operation
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-generating authentication tokens and establishing User ID mappings before actual authentication is needed. The authentication authorization server prepares the token issuance mechanism in advance, so that when authentication is required, the terminal can quickly obtain and use the token without complex real-time processing, thereby maintaining ease of operation while enhancing security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3267704B1Method for unified application authentication in trunking system, server and terminal
Publication Date: 2020.05.06 CHENGDU TD TECH LTD
  • EP3267704B1 patent drawingFigure 1~2
  • EP3267704B1 patent drawingFigure 3~4
  • EP3267704B1 patent drawingFigure 5

AI summary

Embodiments of the present invention provide a unified authentication method for application in a trunking system, a server and a terminal. The method includes: an application service network element of a server receives a registration request transmitted by a terminal and transmits the registration request to an authorization authentication network element, where the registration request carries a token indicating a unique identity of a user initiating the registration request, and the token is assigned by the authorization authentication network element of the server to the user when the user logs onto the terminal; the authorization authentication network element then performs a token authorization to the user according to the token; and finally the application service network element performs an application service interaction with the terminal if the token authorization is passed. During this process, an authentication to individual application service network element is performed through a successful logon of the terminal and an acquisition of the token assigned by the authorization authentication network element to the terminal, the User ID is used as a unified identifier for application services in trunking communications, and an authentication to the application services is effectively combined with a user logon, such that a unified authentication authorization is achieved and security of the trunking system is improved.