Authentication Server Secondary Identifier for UMB Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In ultra mobile broadband (UMB) networks, the secure distribution of a mobile device's network access identifier (NAI) and user profile information is challenging due to the decentralized architecture, which makes it difficult to authenticate access terminals and manage quality of service while maintaining security, especially when the NAI is anonymous and not transmitted over the air.
Innovation Solution
An authentication server generates a secondary user identifier associated with the primary user identifier for an access terminal, allowing secure authentication and distribution of user profile information without exposing the primary user identifier, and manages PMIP keys to ensure secure communication tunnel establishment and rerouting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the NAI is transmitted over the air to the PDSN for authentication and policy retrieval, then the authentication and QoS management can be performed, but the NAI becomes susceptible to snooping and insecure
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the access terminal and the PDSN. The authentication server receives the NAI from the access terminal, performs authentication, and then provides a secondary identifier to the PDSN. This intermediary approach allows authentication to occur without exposing the NAI to the PDSN or transmitting it over the air, thereby resolving the contradiction between enabling authentication and preventing snooping vulnerability.
2Object-affected harmful factors
If the NAI is not sent over the air and anonymous NAI is implemented, then the security against snooping is improved, but the authentication and user profile retrieval become problematic
Solution Approach 1:
The patent segments the identifier system into two parts: a primary identifier (NAI) kept secure and unknown to the PDSN, and a secondary identifier transmitted to the PDSN for authentication and profile retrieval. This segmentation allows the system to maintain security against snooping while enabling authentication operations, as the secondary identifier can be used in place of the NAI for these functions.
Solution Approach 2:
The authentication server acts as a mediator that maps the anonymous secondary identifier back to the primary NAI. When the PDSN needs to retrieve user profiles or perform authentication, it uses the secondary identifier, and the authentication server translates this to the appropriate NAI for profile retrieval, thus maintaining both security and operational ease.
3Reliability
If a PMIPv4 tunnel is used between eBS and AGW, then secure communication can be established, but the MN-HA key distribution to SRNC and AGW becomes complex
Solution Approach 1:
The authentication server serves as an intermediary for MN-HA key distribution. Instead of directly distributing keys between multiple entities (eBS, AGW, SRNC), the authentication server receives the MN-HA key from the access terminal and then distributes it to the appropriate network entities. This centralizes the key management function and simplifies the overall key distribution architecture while maintaining secure PMIPv4 tunnel communication.
Data Source
AI summary
An authentication server may be adapted to (a) authenticate an authentication peer seeking to establish communications via a first network access node; (b) retrieve user profile information associated with the authentication peer; and/or (c) send the user profile information to a network gateway node that facilitates communication services for the authentication peer. A PMIP network node may be adapted to (a) provide wireless network connectivity to an authentication peer via a first network access node; (b) provide a PMIP key to both ends of a PMIP tunnel between the first network access node and a PMIP network node used to provide communications to the authentication peer; (c) provide the PMIP key to a first authenticator associated the first network access node; (d) receive a request at the PMIP network node from a requesting entity to reroute communications for the authentication peer; and/or (e) verify whether the requesting entity knows the PMIP key.


