Authentication Server Mobility Key Generation for Secure Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mobile radio networks face security issues with anonymous subscribers, as any node can send a registration request to a home agent, potentially misleading it about a mobile station's location, leading to unauthorized data packet forwarding and lack of secure authentication and authorization.

Innovation Solution

An authentication server generates and stores a unique mobility key for each subscriber upon registration, using a derivation function to assign it a mobility identity, ensuring cryptographic protection of mobility signaling messages by providing the corresponding key to the home agent upon request.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If any node can send a registration request to a home agent without authentication, then the network allows anonymous subscribers and easy registration, but security is compromised allowing unauthorized data packet forwarding and location misinformation

Engineering Contradiction:
Improvenetwork access for anonymous subscribersVSAvoidsecurity and authentication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by generating and storing mobility keys for subscribers during the initial network registration process, before any mobility signaling occurs. The authentication server proactively creates these cryptographic credentials and associates them with subscriber identities, ensuring security is established in advance rather than reacting to potential threats later

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication server as an intermediary between subscribers and home agents. This mediator generates mobility keys, manages subscriber authentication, and provides cryptographic protection for mobility signaling messages, thereby securing the network without preventing anonymous subscriber access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a mobility key is generated and stored for each subscriber during registration, then cryptographic protection of mobility signaling messages is achieved, but the authentication server requires additional storage and processing resources

Engineering Contradiction:
Improvecryptographic protection of mobility signalingVSAvoidauthentication server storage and processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming subscriber identity information into compact cryptographic representations (mobility keys and mobility identities) that can be efficiently stored and processed. The derivation function converts subscriber identifiers into fixed-length cryptographic parameters, reducing storage requirements while maintaining security

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent uses copying by creating derived mobility identities from subscriber identities through a deterministic derivation function. These derived identifiers serve as compact references that enable key retrieval without storing complete subscriber profiles, reducing authentication server storage burden

Inventive Principle:
Principle #26Copying

3Measurement precision

If a derivation function is used to assign mobility identity from subscriber identity, then unique key assignment is achieved, but the system requires additional computational overhead for identity derivation and matching

Engineering Contradiction:
Improveunique mobility key assignment to subscribersVSAvoidcomputational time for identity derivation
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing mobility keys during the initial network registration process, before any mobility signaling or key retrieval operations occur. This upfront computation eliminates the need for time-consuming key generation during critical mobility events, reducing latency in key assignment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating derived mobility identities through deterministic derivation from subscriber identities. This copying mechanism enables rapid identity matching and key retrieval operations, as the derivation function produces consistent, reproducible results without requiring complex computational verification during key assignment

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9043599B2Method and server for providing a mobility key
Publication Date: 2015.05.26 SIEMENS AG
  • US9043599B2 patent drawing
  • US9043599B2 patent drawing
  • US9043599B2 patent drawing

AI summary

A method and authentication server provide a mobile key. According to the method, upon receipt of an authentication message (access authentication) that is transmitted when a subscriber logs on to the network, the authentication server extracts a subscriber identification contained in said message and generates a corresponding mobile key, which is stored together with the respective extracted subscriber identification. Upon subsequent receipt of a key request message (key request) that is transmitted when a subscriber registers, the authentication server extracts a mobile identification of the subscriber contained in said message and searches for an identical mobile identification, which can be derived in accordance with a configurable derivation function from a subscriber identification that is stored in the authentication server. Once a derived mobile identification that is identical or can be uniquely assigned to the extracted mobile identification has been found, the authentication server provides the stored corresponding mobile key that has been generated, to cryptographically protect the mobile signaling messages of the registered subscriber.