Mobile IP Binding Update Authentication Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile telecommunications, the existing systems require frequent messaging between the Home Agent (HA) and the Home AAA Server (AAAH) for key request and response, leading to inefficient and non-simple authentication of Binding Update messages.

Innovation Solution

Deriving an update message signing key and transmitting it to the visited network or mobile node for signing the update message, allowing for independent authentication by the Home Agent without repeated messaging with the AAAH, using a signing key generator and authentication key derivation based on long-term keys and user terminal identification data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If frequent messaging between Home Agent and Home AAA Server is used for key request and response, then authentication of Binding Update messages can be performed, but the authentication procedure becomes inefficient and complex

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-distributing update message signing keys from the Home AAA Server to the Home Agent during initial authentication. This allows the Home Agent to independently verify Binding Update messages without requiring frequent real-time key requests, thus maintaining authentication reliability while significantly improving efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process is segmented into two phases: initial key distribution phase (between HA and AAAH) and message verification phase (independent HA operation). This segmentation allows the system to maintain security through centralized key management while achieving efficient independent verification, resolving the contradiction between reliability and productivity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If frequent messaging between Home Agent and Home AAA Server is used for key request and response, then authentication can be performed, but the dependency of AAAH on update messages increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key verification function from the Home AAA Server and places it in the Home Agent. By distributing signing keys in advance, the verification capability is taken out from the centralized AAAH, reducing its dependency on update messages and simplifying the overall system architecture while maintaining authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The Home Agent is enabled to perform self-service authentication by independently verifying Binding Update messages using pre-distributed signing keys. This eliminates the need for continuous AAAH involvement in each authentication event, reducing system complexity and AAAH dependency while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If keys are stored in the system for authentication, then authentication can be performed, but the system requires key storage which reduces scalability

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent employs disposable short-lived signing keys that are distributed temporarily for authentication purposes and then discarded. These keys replace long-term stored keys, allowing the system to maintain authentication reliability without requiring persistent key storage, thereby improving scalability and adaptability.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8117454B2Fast update message authentication with key derivation in mobile IP systems
Publication Date: 2012.02.14 NOKIA TECHNOLOGIES OY
  • US8117454B2 patent drawing
  • US8117454B2 patent drawing
  • US8117454B2 patent drawing

AI summary

The present invention performs a Binding Update or a Location Update message authentication independently and terminal-specifically in a home SAE gateway. A key, which is derived in a home AAA server from an initially set long term key, is given to a visited network for encrypting the update messages in Proxy Mobile IP. In Client Mobile IP, the key is transmitted to a mobile node for update message encryption. When the update message is received in the home SAE gateway, the key can be derived independently in the home SAE gateway without any key requests between the gateway and the home AAA server. Thus, it is possible to authenticate the binding or location update messages by verifying the two signatures. The present invention can also be implemented on a lower hierarchy of the system. The invention can be implemented in 3GPP standard releases enhanced with LTE technology, for instance.