Trusted Third Party Authentication in Access Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication mechanisms in computer networks require entities to obtain and verify public key certificates before authentication, which is challenging in access networks with limited resources and structures that do not comply with the 'user-access point-server' structure, such as in access networks where users cannot access the network until authentication is complete.

Innovation Solution

A method and system for entity public key obtaining, certificate verification, and authentication using an online trusted third party that allows entities to request and verify public key certificates within the 'user-access point-server' structure, involving message exchanges and signature verification to determine authentication status without needing pre-existing valid public keys or certificate statuses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication mechanisms (CRL/OCSP) are used, then public key certificate verification can be performed, but the system cannot operate in access networks where users cannot access the network before authentication

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidaccess availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trusted third party (TP) as an intermediary that performs certificate verification on behalf of the access point. The TP acts as a mediator between the user and the access point, checking certificate validity without requiring the user to directly access external certificate status services. This resolves the contradiction by enabling authentication reliability through TP-mediated verification while maintaining access availability since the user doesn't need network access before authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs certificate verification actions in advance by having the access point query the trusted third party before authentication occurs. The TP pre-verifies certificate status and provides verification results to the access point, so that when authentication is needed, the verification is already complete. This eliminates the need for users to access external services before authentication while ensuring reliable certificate verification.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If pre-existing public key or certificate status knowledge is required, then authentication can proceed, but the system becomes incompatible with access networks lacking prior certificate information

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidnetwork structure compatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The trusted third party serves as an intermediary that provides certificate status information to the access point without requiring the access point to have pre-existing knowledge. The TP mediates the information flow, allowing the access point to obtain verified certificate status dynamically rather than relying on pre-configured data. This enables authentication efficiency while adapting to various network structures including those without prior certificate information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal authentication mechanism that works across different network structures by using the trusted third party as a common reference point. The system can operate in environments with pre-existing certificate knowledge or without it, making it adaptable to multiple network configurations. The TP provides a universal service that accommodates both scenarios, enhancing the system's versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If separate certificate verification protocols are used, then certificate status can be checked, but the protocol complexity increases and compatibility with existing access network structures becomes difficult

Engineering Contradiction:
Improvecertificate verification accuracyVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the certificate verification function with the existing authentication protocol by having the access point include verification requests within its authentication messages to the trusted third party. Rather than using separate OCSP or CRL protocols, the verification is integrated into the authentication flow. This maintains verification accuracy while reducing protocol complexity and improving compatibility with existing access network structures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The trusted third party implements a universal verification mechanism that can handle multiple certificate status scenarios through a single integrated approach. The TP's verification service is multi-functional, accommodating different network configurations and authentication scenarios without requiring separate specialized protocols. This reduces overall system complexity while maintaining verification reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2472772B1Method and system for entity public key acquiring, certificate validation and authentication by introducing an online credible third party
Publication Date: 2020.05.06 CHINA IWNCOMM
  • EP2472772B1 patent drawingFigure 1~2
  • EP2472772B1 patent drawingFigure 3

AI summary

A method and system for entity public key acquiring, certificate validation and authentication by introducing an online credible third party is disclosed. The method includes the following steps: 1) an entity B transmits a message 1 to an entity A; 2) the entity A transmits a message 2 to a credible third party TP after receiving the message 1; 3) the credible third party TP determines the response RepTA after receiving the message 2; 4) the credible third party TP returns a message 3 to the entity A; 5) the entity A returns a message 4 to the entity B after receiving the message 3; 6) the entity B receives the message 4; 7) the entity B transmits a message 5 to the entity A; 8) the entity A receives the message 5. The present invention can achieve public key acquisition, certificate validation and authentication of the entity by integrating them in one protocol, thereby facilitate the execution efficiency and the effect of the protocol and facilitate the combination with various public key acquisition and public key certificate state enquiry protocols. The present invention suits with a "user-access point-server" access network structure to meet the authentication requirement of the access network.