AKA Parameter Transfer for M2M Authentication Efficiency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication and key agreement (AKA) schemes in telecommunications networks are inefficient, particularly for machine-to-machine (M2M) communications, which involve numerous devices that rarely access the network, leading to burdensome message exchanges and resource wastage.
Innovation Solution
A method that transfers AKA parameters during a terminal session to enable authentication and key agreement for subsequent sessions, reducing the need for separate requests and improving efficiency by allowing immediate access to authentication messages and keys, thereby streamlining the authentication process and saving resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional AKA authentication procedure is used for each terminal session, then security is maintained, but message exchange burden increases and authentication efficiency decreases
Solution Approach 1:
The patent applies preliminary action by performing authentication and key agreement procedures in advance during an active terminal session. The network node generates and transfers AKA parameters (including authentication vectors and keys) to the terminal before the session ends, so that when the session is re-established, authentication can proceed quickly using pre-computed parameters without requiring a full authentication exchange.
Solution Approach 2:
The patent makes AKA parameters universal by designing them to be valid across multiple terminal sessions. The authentication vectors and keys generated during one session can be reused in subsequent sessions, allowing the same parameters to serve multiple authentication purposes and reducing the need for repeated authentication procedures.
2Loss of time
If AKA parameters are transferred during terminal session n, then authentication for subsequent session n+m is enabled, but security risk of parameter interception increases
Solution Approach 1:
The patent applies preliminary action by performing authentication and key agreement procedures in advance during an active terminal session. The network node generates and transfers AKA parameters (including authentication vectors and keys) to the terminal before the session ends, so that when the session is re-established, authentication can proceed quickly using pre-computed parameters without requiring a full authentication exchange.
Solution Approach 2:
The patent converts the potential security harm of transmitting AKA parameters over the radio interface into a benefit by designing the parameters to be session-bound and time-limited. The parameters include identifiers that tie them to specific sessions, and the network node validates these identifiers during subsequent authentications, ensuring that even if parameters are intercepted, they cannot be reused outside their intended session context.
3Reliability
If M2M devices perform full authentication procedure for each rare network access, then security is ensured, but resource consumption increases
Solution Approach 1:
The patent applies preliminary action by performing authentication and key agreement procedures in advance during an active terminal session. The network node generates and transfers AKA parameters (including authentication vectors and keys) to the terminal before the session ends, so that when the session is re-established, authentication can proceed quickly using pre-computed parameters without requiring a full authentication exchange.
Solution Approach 2:
The patent applies partial action by performing only the necessary minimum authentication steps during session re-establishment. Instead of executing a complete authentication procedure involving multiple message exchanges and computational operations, the terminal and network node use pre-computed AKA parameters to perform a streamlined authentication that consumes significantly less energy while maintaining security.
Data Source
Figure 1
Figure 2A~2B
Figure 3A
AI summary
The invention relates to AKA procedures for terminals in a network. A method for enabling authentication and/or key agreement for a terminal in a network is disclosed. The method involves the transfer of at least one AKA parameter (RANDn+m ; RANDn+m, AUTNn+m) from the network to the terminal during a terminal session n. The AKA parameter enables authentication and/or key agreement procedure of the terminal in the network for a subsequent terminal session n+m.