WLAN Authentication Token Intermediary for Secure Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Accessing restricted WLAN hotspots is problematic due to security concerns, inconvenience in entering payment details, and inefficiency in the login process, especially when users need to quickly connect to the internet for packet-based communication systems.
Innovation Solution
A method where a user terminal requests an authentication token from a trusted network node via an unrestricted channel, using domain name server protocol and tunnelling, to derive login information and authenticate with the access node, allowing secure and efficient access to the communication network using pre-existing payment credits from the packet-based communication system provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manually enter payment details and login credentials at hotspot login servers, then access to restricted WLAN hotspots can be obtained, but security risks increase and user convenience decreases
Solution Approach 1:
The patent introduces an intermediary authentication system that acts as a trusted third party between the user and the hotspot access node. The user's home authentication server verifies credentials and generates authentication tokens, preventing direct exposure of sensitive payment and login information to potentially untrusted hotspot servers while maintaining secure access.
Solution Approach 2:
The system performs preliminary authentication and credential verification through the user's home authentication server before the user attempts to access the hotspot. Authentication tokens are pre-generated and validated, so that when the user connects to the hotspot, the access is already authorized without requiring manual entry of sensitive information at the hotspot server.
2Productivity
If users manually log in to hotspots with payment details, then access can be granted, but the process becomes time-consuming and inefficient
Solution Approach 1:
Authentication credentials and authorization tokens are verified in advance through the home authentication server before the user needs to access the hotspot. This preliminary authentication eliminates the need for time-consuming manual login processes at the hotspot, allowing users to connect quickly by simply presenting their pre-validated credentials.
3Reliability
If direct authentication at hotspot servers is used, then access control can be enforced, but security risks increase due to exposure of sensitive information
Solution Approach 1:
The home authentication server serves as a trusted intermediary that handles all sensitive authentication and payment information verification. The hotspot access node only receives validated authentication tokens without ever handling or storing sensitive user information, thus maintaining access control while eliminating security exposure risks associated with direct authentication at potentially untrusted hotspot servers.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of authenticating a user terminal (104) with an access node (108) providing restricted access to a communication network (106,126), comprising: the user terminal transmitting a request for an authentication token to a trusted network node (128) via an unrestricted channel on the access node, the request comprising a network identity for a user of the user terminal; the network node verifying the identity of the user using the network identity, generating an authentication token and transmitting the authentication token to the user terminal via the unrestricted channel; the user terminal deriving login information from the authentication token and providing the login information to the access node; and the access node authenticating the login information and removing the restricted access such that the communication network can be accessed by the user terminal.