Group Authentication Key Agreement for Wireless Relay Handoffs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication and key agreement protocols in wireless communication systems, such as IEEE Std 802.16e, face challenges with high handoff latency, bandwidth consumption, large storage requirements, and synchronization needs due to frequent handoffs of mobile relay stations (MRS) between base stations, especially when using EAP-SIM and EAP-AKA authentication protocols.
Innovation Solution
A Group Authentication and Key Agreement (G-AKA) method that configures group information for mobile relay stations and base stations, allowing for group authentication and key generation using a group signature scheme and key agreement methods like Diffie-Hellman, reducing management message transmission and storage needs by authenticating a group instead of individual stations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual authentication protocols (EAP-SIM, EAP-AKA) are used for each mobile relay station, then security is maintained, but authentication delay and bandwidth consumption increase significantly during frequent handoffs
Solution Approach 1:
The patent merges multiple individual authentication requests into a single group authentication process. When a mobile relay station handoffs to a new base station, instead of performing complete EAP-SIM or EAP-AKA authentication individually, the system performs group authentication where multiple MRSs in the same group can be authenticated simultaneously through one authentication vector, significantly reducing authentication delay while maintaining security
Solution Approach 2:
The patent implements preliminary group authentication configuration where authentication vectors are pre-generated and stored for groups of mobile relay stations. This allows fast re-authentication during handoff by using pre-computed authentication data, avoiding the need to perform complete authentication protocols from scratch and thus reducing authentication delay
2Reliability
If individual authentication protocols are used for each mobile relay station, then individual security is ensured, but bandwidth consumption and storage requirements increase due to frequent handoffs
Solution Approach 1:
The patent combines multiple individual authentication transactions into a single group authentication transaction. Instead of transmitting separate authentication vectors and messages for each MRS during handoff, the system transmits a single group authentication vector that serves multiple MRSs, significantly reducing bandwidth consumption while maintaining individual security through unique authentication keys for each station
Solution Approach 2:
The patent creates a universal group authentication mechanism that can serve multiple mobile relay stations simultaneously. The group authentication vector serves as a multi-functional credential that enables authentication for all members of the group, reducing the overall quantity of authentication data that needs to be transmitted across the network
3Reliability
If individual authentication protocols are used for each mobile relay station, then individual authentication is complete, but storage requirements become large to support frequent handoffs
Solution Approach 1:
The patent merges individual authentication storage requirements into group-level storage. Instead of storing complete authentication vectors for each individual MRS in every base station, the system stores group authentication vectors that can be reused by multiple MRSs, significantly reducing the volume of stored authentication data while maintaining individual authentication capability
Solution Approach 2:
The patent uses copying of group authentication vectors to multiple base stations instead of storing individual authentication data. When an MRS handoffs between base stations, the same group authentication vector can be copied and used across different base stations, eliminating the need for each base station to store complete individual authentication credentials for all possible MRSs
Data Source
AI summary
A method for operating a wireless communication system including a mobile relay station group, a base station group, and an authentication server, includes: configuring, by the authentication server, group information into the mobile relay station group and the base station group; requesting, by the base station group, group authentication data for the mobile relay station group from the authentication server; and performing authentication between a member of the mobile relay station group and a member of the base station group and generating an authentication key individually by the member of the mobile relay station group and the member of the base station group. Also disclosed is a system for carrying out the method.


