Mobile Node Preauthentication via Trust Transitivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Vertical handover in mobile networks experiences significant delays due to authentication processes, particularly during transitions between different communication protocols, leading to latency issues and computational burdens on mobile nodes.

Innovation Solution

A method of preauthenticating a mobile node by sending preauthentication requests from the current point of attachment to one or more possible points of attachment using a transitivity of trust between the mobile node, the current point of attachment, and authentication servers, thereby reducing processing and signaling delays.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Force

If preauthentication is performed by communicating authentication messages through the current point of attachment to the next point of attachment, then authentication can be initiated in advance, but the overall authentication time increases due to the extra hop through the current point of attachment

Engineering Contradiction:
Improveauthentication initiation timingVSAvoidauthentication completion time
Core Design Contradiction:
ForceVSLoss of time

Solution Approach 1:

The patent extracts the authentication message transmission path from the current point of attachment, allowing the mobile node to communicate authentication messages directly with the next point of attachment without routing through the current point of attachment. This removes the unnecessary hop and reduces authentication time while still enabling advance initiation.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If full authentication is performed during handover between different network types, then security credentials are verified, but the latency becomes too high to sustain ongoing connections

Engineering Contradiction:
Improvesecurity verificationVSAvoidhandover latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication actions by allowing the mobile node to initiate and complete authentication with the next point of attachment before actually performing the handover. This preliminary action ensures security credentials are verified in advance, so when handover occurs, authentication is already complete, eliminating the latency issue during connection switching.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If preauthentication is started up to 31 seconds in advance to achieve acceptable latency, then authentication can be completed before handover, but this is not feasible for mobile nodes moving at high speed where next points of access may not be within range

Engineering Contradiction:
Improveauthentication lead timeVSAvoidmobility adaptability
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The patent makes the authentication timing dynamic by allowing the mobile node to initiate preauthentication at any point before handover is needed, rather than requiring a fixed 31-second lead time. The system adapts the authentication timing based on the actual handover scenario, enabling preauthentication to start whenever the next point of attachment becomes visible or selectable, which works for both slow and high-speed mobility scenarios.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9491619B2Method and system for preauthenticating a mobile node
Publication Date: 2016.11.08 INFOSYS LTD
  • US9491619B2 patent drawing
  • US9491619B2 patent drawing
  • US9491619B2 patent drawing

AI summary

A method of preauthenticating a mobile node in advance of a switch from a current point of attachment (CPoA) to a next point of attachment (NPoA) is disclosed. One or more preauthentication requests are received at the CPoA. The one or more preauthentication requests include a proxy assignment from the mobile node. Each of the one or more preauthentication requests corresponds to one of one or more possible points of attachment (PPoAs). Using the CPoA, the mobile node is preauthenticated with the one or more PPoAs using a transitivity of trust between the mobile node, the CPoA, and one or more authentication servers.