Authentication Proxy for Fast Handover in Communications Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication protocols, such as EAP, require significant signaling with the user's home network during handovers between access networks, leading to slow and noticeable disruptions in ongoing sessions, and lack efficient methods for maintaining user privacy and security.

Innovation Solution

A terminal-centric approach using an authentication proxy that receives a temporary, access-independent identifier and session key from the home network, maps and stores them, and derives new session keys for each access network, allowing secure handovers without relying on the home network for re-authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAP authentication protocol is used for handover between access networks, then security is maintained through home network involvement, but authentication time increases causing noticeable disruption to user session

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements fast re-authentication by pre-establishing authentication credentials and using cached authentication data from previous successful authentications. When a user moves to a new access network, the system performs a simplified re-authentication using pre-computed authentication vectors and cached session information, avoiding the need to contact the home network for full authentication. This preliminary preparation of authentication data significantly reduces authentication time while maintaining security through verified credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication proxy or intermediary entity that caches authentication data and session information locally. This intermediary enables fast re-authentication by mediating between the user equipment and the home network, allowing authentication decisions to be made locally using cached credentials without requiring real-time communication with the home network, thus reducing authentication time while preserving security through the use of pre-verified authentication data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full EAP authentication is performed during handover, then user credentials are verified securely, but signaling overhead increases causing slow authentication

Engineering Contradiction:
Improvecredential verificationVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial authentication action by using cached authentication data and pre-computed authentication vectors for fast re-authentication. Instead of performing a complete EAP authentication sequence, the system uses a simplified verification process that checks previously obtained authentication credentials against cached data. This partial authentication approach maintains sufficient security verification while dramatically reducing signaling overhead and authentication time compared to full EAP authentication.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If network centric handover management is used, then smart handover decisions can be made, but integration complexity between different access networks increases

Engineering Contradiction:
Improvehandover optimizationVSAvoidnetwork integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements terminal-centric handover management where the user equipment autonomously performs handover decisions and execution based on local measurements and pre-configured parameters. The terminal monitors signal quality, evaluates available access networks, and autonomously initiates handover procedures without requiring complex network coordination or integration between different access networks. This self-service approach maintains adaptability through local intelligence while significantly reducing network integration complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8885831B2Managing user access in a communications network
Publication Date: 2014.11.11 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US8885831B2 patent drawing
  • US8885831B2 patent drawing
  • US8885831B2 patent drawing

AI summary

A method of operating a node for performing handover between access networks wherein a user has authenticated for network access in a first access network. The method comprises receiving from a home network a first session key and a temporary identifier allocated to the user for the duration of a communication session. The identifier is mapped to the first session key, and the mapped identifier and key are stored at the node. A second session key is derived from the first session key and the second session key is sent to an access network, and the identifier sent to a user terminal. When the user subsequently moves to a second access network, the node receives the identifier from the user terminal. The node then retrieves the first session key mapped to the received identifier, derives a third session key and sends the third session key to the second access network.