Authentication Server Mobility Key Generation for Secure Signaling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional mobile radio networks face security issues with anonymous subscribers, as any node can send a registration request to a home agent, potentially misleading it about a mobile station's location, leading to unauthorized data packet forwarding and lack of secure authentication and authorization.
Innovation Solution
An authentication server generates and stores a unique mobility key for each subscriber upon registration, using a derivation function to assign it a mobility identity, ensuring cryptographic protection of mobility signaling messages by providing the corresponding key to the home agent upon request.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If any node can send a registration request to a home agent without authentication, then the network allows anonymous subscribers and easy registration, but security is compromised allowing unauthorized data packet forwarding and location misinformation
Solution Approach 1:
The patent applies preliminary action by generating and storing mobility keys for subscribers during the initial network registration process, before any mobility signaling occurs. The authentication server proactively creates these cryptographic credentials and associates them with subscriber identities, ensuring security is established in advance rather than reacting to potential threats later
Solution Approach 2:
The patent introduces an authentication server as an intermediary between subscribers and home agents. This mediator generates mobility keys, manages subscriber authentication, and provides cryptographic protection for mobility signaling messages, thereby securing the network without preventing anonymous subscriber access
2Reliability
If a mobility key is generated and stored for each subscriber during registration, then cryptographic protection of mobility signaling messages is achieved, but the authentication server requires additional storage and processing resources
Solution Approach 1:
The patent applies parameter changes by transforming subscriber identity information into compact cryptographic representations (mobility keys and mobility identities) that can be efficiently stored and processed. The derivation function converts subscriber identifiers into fixed-length cryptographic parameters, reducing storage requirements while maintaining security
Solution Approach 2:
The patent uses copying by creating derived mobility identities from subscriber identities through a deterministic derivation function. These derived identifiers serve as compact references that enable key retrieval without storing complete subscriber profiles, reducing authentication server storage burden
3Measurement precision
If a derivation function is used to assign mobility identity from subscriber identity, then unique key assignment is achieved, but the system requires additional computational overhead for identity derivation and matching
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing mobility keys during the initial network registration process, before any mobility signaling or key retrieval operations occur. This upfront computation eliminates the need for time-consuming key generation during critical mobility events, reducing latency in key assignment
Solution Approach 2:
The patent uses copying by creating derived mobility identities through deterministic derivation from subscriber identities. This copying mechanism enables rapid identity matching and key retrieval operations, as the derivation function produces consistent, reproducible results without requiring complex computational verification during key assignment
Data Source
AI summary
A method and authentication server provide a mobile key. According to the method, upon receipt of an authentication message (access authentication) that is transmitted when a subscriber logs on to the network, the authentication server extracts a subscriber identification contained in said message and generates a corresponding mobile key, which is stored together with the respective extracted subscriber identification. Upon subsequent receipt of a key request message (key request) that is transmitted when a subscriber registers, the authentication server extracts a mobile identification of the subscriber contained in said message and searches for an identical mobile identification, which can be derived in accordance with a configurable derivation function from a subscriber identification that is stored in the authentication server. Once a derived mobile identification that is identical or can be uniquely assigned to the extracted mobile identification has been found, the authentication server provides the stored corresponding mobile key that has been generated, to cryptographically protect the mobile signaling messages of the registered subscriber.


