Mobile Terminal Handover Authentication via Pre-Shared Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile terminal authentication processes during handover are inefficient due to the need for multiple round-trips to a remote AAA server, increasing handover latency, and difficulties in exchanging session keys between different NAS operators, which also incur high over-the-air signaling costs.

Innovation Solution

A method that eliminates the need for information exchange between a backend authentication server and a NAS by maintaining a list of potential NASs, transmitting authorization information, and using a Pre-Shared Key (PSK) method for authentication, allowing the new NAS to authenticate the mobile terminal without relying on the backend server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the mobile terminal performs full authentication procedure with the backend AAA server during handover, then authentication security is ensured, but handover latency increases due to multiple round-trips

Engineering Contradiction:
Improveauthentication securityVSAvoidhandover latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-distributing authentication credentials (such as pre-shared keys or authentication vectors) to potential target NASs before handover occurs. This allows the mobile terminal to be authenticated at the new NAS without requiring real-time communication with the backend AAA server, thus maintaining security while reducing handover latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the authentication function from the backend AAA server and relocates it to the local NAS by distributing authentication credentials in advance. This extraction allows the NAS to perform local authentication without depending on the backend server during handover, thereby reducing latency while maintaining authentication security.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If session keys are exchanged between different NAS operators during handover, then inter-NAS mobility is enabled, but security association and operator coordination complexity increase

Engineering Contradiction:
Improveinter-NAS mobilityVSAvoidsecurity association complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses copying by distributing copies of authentication credentials (such as pre-shared keys or authentication vectors) from the home NAS to potential target NASs in advance. This eliminates the need for real-time session key exchange between different operators during handover, simplifying security associations while enabling seamless inter-NAS mobility.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies preliminary action by pre-establishing security associations between NASs before handover occurs. Authentication credentials are distributed in advance to potential target NASs, eliminating the need for complex real-time coordination and session key exchange during actual handover between different operators.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If the mobile terminal performs authentication with potential target NASs using PANA protocol, then pre-authentication is achieved, but over-the-air signaling cost increases

Engineering Contradiction:
Improvehandover latencyVSAvoidover-the-air signaling cost
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The patent extracts the authentication signaling from the over-the-air interface and moves it to the network side by pre-distributing authentication credentials to target NASs. This eliminates the need for PANA protocol exchanges over the air during handover, reducing signaling costs while maintaining pre-authentication benefits.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses copying by distributing authentication credentials to target NASs through network infrastructure before handover. This replaces expensive over-the-air PANA signaling with efficient network-side credential distribution, achieving pre-authentication without high signaling costs.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8494487B2Method and apparatus for authenticating mobile terminal on handover
Publication Date: 2013.07.23 SAMSUNG ELECTRONICS CO LTD
  • US8494487B2 patent drawing
  • US8494487B2 patent drawing
  • US8494487B2 patent drawing

AI summary

A method and apparatus for authenticating a mobile terminal are provided. A list of potential Network Access Servers (NASs) corresponding to a NAS are maintained in a backend authentication server, authorization information corresponding to each of the potential NASs is transmitted, from the backend authentication server to each of the potential NASs, when the mobile terminal is authenticated via the NAS. The mobile terminal detects whether a new NAS is pre-authenticated, when the mobile terminal moves to a domain of the new NAS, the new NAS detects whether the mobile terminal is pre-authenticated, and the new NAS authenticates the mobile terminal via a Pre-Shared Key (PSK) method, when the mobile terminal and the new NAS are pre-authenticated.