Generic Authentication Architecture Mobile IP Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies cannot utilize the Generic Authentication Architecture for Mobile Internet Protocol key distribution, as they require specific parameters like Mobile Node Network Access Identifier, symmetric key, and Security Parameter Index, which are not provisioned by Generic Authentication Architecture.

Innovation Solution

Adopting the Generic Authentication Architecture bootstrapping procedure between a mobile terminal device and a Bootstrapping Server Function to derive a shared key and Bootstrapping Transaction Identifier, then using these to derive a Network Application Function-specific key for message authentication and Mobile IP registration requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Generic Authentication Architecture is used for authentication, then authentication capability is provided, but Mobile IP key distribution parameters cannot be obtained

Engineering Contradiction:
Improveauthentication capabilityVSAvoidMobile IP key distribution parameters
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary mechanism (authentication server and key derivation function) that bridges Generic Authentication Architecture and Mobile IP key distribution. The authentication server acts as a mediator that receives authentication requests from mobile stations, generates authentication vectors, and derives the necessary Mobile IP key distribution parameters (symmetric key and security parameter index) from the authentication process, thereby enabling parameter transmission without direct integration between the two systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication and key distribution processes into distinct functional components. The authentication phase (using Generic Authentication Architecture) is separated from the key distribution phase (providing Mobile IP parameters), with a clear interface between them. This segmentation allows each phase to operate independently while ensuring that the output of the authentication phase feeds into the key distribution phase through defined protocols.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If Mobile IP protocol specifications are modified to support Generic Authentication Architecture, then key distribution compatibility is achieved, but protocol complexity increases

Engineering Contradiction:
Improvekey distribution compatibilityVSAvoidprotocol specifications
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework that serves multiple functions: it provides Generic Authentication Architecture authentication while simultaneously generating Mobile IP key distribution parameters. The authentication server and key derivation mechanism are designed to be multi-functional, handling both authentication verification and key parameter generation without requiring separate systems, thereby avoiding protocol complexity increases while achieving compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service key distribution where the mobile station autonomously derives its own Mobile IP key distribution parameters (symmetric key and security parameter index) from the authentication process. The authentication vector and key derivation function allow the mobile station to self-generate the necessary cryptographic material without requiring manual configuration or complex protocol negotiations, simplifying the overall system while maintaining compatibility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7545768B2Utilizing generic authentication architecture for mobile internet protocol key distribution
Publication Date: 2009.06.09 WSOU INVESTMENTS LLC
  • US7545768B2 patent drawing
  • US7545768B2 patent drawing
  • US7545768B2 patent drawing

AI summary

The invention allows utilizing Generic Authentication Architecture for Mobile Internet Protocol key distribution. A Generic Authentication Architecture bootstrapping is performed between a mobile terminal device and a Bootstrapping Server Function. In an embodiment a resulting Bootstrapping Transaction Identifier is sent to a Home Agent which uses it to obtain a Home Agent specific key to be used in authenticating a Mobile Internet Protocol Registration Request.