Mobile IP Binding Update Authentication Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile telecommunications, the existing systems require frequent messaging between the Home Agent (HA) and the Home AAA Server (AAAH) for key request and response, leading to inefficient and non-simple authentication of Binding Update messages.
Innovation Solution
Deriving an update message signing key and transmitting it to the visited network or mobile node for signing the update message, allowing for independent authentication by the Home Agent without repeated messaging with the AAAH, using a signing key generator and authentication key derivation based on long-term keys and user terminal identification data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If frequent messaging between Home Agent and Home AAA Server is used for key request and response, then authentication of Binding Update messages can be performed, but the authentication procedure becomes inefficient and complex
Solution Approach 1:
The patent applies preliminary action by pre-distributing update message signing keys from the Home AAA Server to the Home Agent during initial authentication. This allows the Home Agent to independently verify Binding Update messages without requiring frequent real-time key requests, thus maintaining authentication reliability while significantly improving efficiency.
Solution Approach 2:
The authentication process is segmented into two phases: initial key distribution phase (between HA and AAAH) and message verification phase (independent HA operation). This segmentation allows the system to maintain security through centralized key management while achieving efficient independent verification, resolving the contradiction between reliability and productivity.
2Reliability
If frequent messaging between Home Agent and Home AAA Server is used for key request and response, then authentication can be performed, but the dependency of AAAH on update messages increases
Solution Approach 1:
The patent extracts the key verification function from the Home AAA Server and places it in the Home Agent. By distributing signing keys in advance, the verification capability is taken out from the centralized AAAH, reducing its dependency on update messages and simplifying the overall system architecture while maintaining authentication reliability.
Solution Approach 2:
The Home Agent is enabled to perform self-service authentication by independently verifying Binding Update messages using pre-distributed signing keys. This eliminates the need for continuous AAAH involvement in each authentication event, reducing system complexity and AAAH dependency while maintaining security.
3Reliability
If keys are stored in the system for authentication, then authentication can be performed, but the system requires key storage which reduces scalability
Solution Approach 1:
The patent employs disposable short-lived signing keys that are distributed temporarily for authentication purposes and then discarded. These keys replace long-term stored keys, allowing the system to maintain authentication reliability without requiring persistent key storage, thereby improving scalability and adaptability.
Data Source
AI summary
The present invention performs a Binding Update or a Location Update message authentication independently and terminal-specifically in a home SAE gateway. A key, which is derived in a home AAA server from an initially set long term key, is given to a visited network for encrypting the update messages in Proxy Mobile IP. In Client Mobile IP, the key is transmitted to a mobile node for update message encryption. When the update message is received in the home SAE gateway, the key can be derived independently in the home SAE gateway without any key requests between the gateway and the home AAA server. Thus, it is possible to authenticate the binding or location update messages by verifying the two signatures. The present invention can also be implemented on a lower hierarchy of the system. The invention can be implemented in 3GPP standard releases enhanced with LTE technology, for instance.


