Mobile Terminal Handover Authentication via Pre-Shared Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile terminal authentication processes during handover are inefficient due to the need for multiple round-trips to a remote AAA server, increasing handover latency, and difficulties in exchanging session keys between different NAS operators, which also incur high over-the-air signaling costs.
Innovation Solution
A method that eliminates the need for information exchange between a backend authentication server and a NAS by maintaining a list of potential NASs, transmitting authorization information, and using a Pre-Shared Key (PSK) method for authentication, allowing the new NAS to authenticate the mobile terminal without relying on the backend server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the mobile terminal performs full authentication procedure with the backend AAA server during handover, then authentication security is ensured, but handover latency increases due to multiple round-trips
Solution Approach 1:
The patent applies preliminary action by pre-distributing authentication credentials (such as pre-shared keys or authentication vectors) to potential target NASs before handover occurs. This allows the mobile terminal to be authenticated at the new NAS without requiring real-time communication with the backend AAA server, thus maintaining security while reducing handover latency.
Solution Approach 2:
The patent extracts the authentication function from the backend AAA server and relocates it to the local NAS by distributing authentication credentials in advance. This extraction allows the NAS to perform local authentication without depending on the backend server during handover, thereby reducing latency while maintaining authentication security.
2Adaptability or versatility
If session keys are exchanged between different NAS operators during handover, then inter-NAS mobility is enabled, but security association and operator coordination complexity increase
Solution Approach 1:
The patent uses copying by distributing copies of authentication credentials (such as pre-shared keys or authentication vectors) from the home NAS to potential target NASs in advance. This eliminates the need for real-time session key exchange between different operators during handover, simplifying security associations while enabling seamless inter-NAS mobility.
Solution Approach 2:
The patent applies preliminary action by pre-establishing security associations between NASs before handover occurs. Authentication credentials are distributed in advance to potential target NASs, eliminating the need for complex real-time coordination and session key exchange during actual handover between different operators.
3Loss of time
If the mobile terminal performs authentication with potential target NASs using PANA protocol, then pre-authentication is achieved, but over-the-air signaling cost increases
Solution Approach 1:
The patent extracts the authentication signaling from the over-the-air interface and moves it to the network side by pre-distributing authentication credentials to target NASs. This eliminates the need for PANA protocol exchanges over the air during handover, reducing signaling costs while maintaining pre-authentication benefits.
Solution Approach 2:
The patent uses copying by distributing authentication credentials to target NASs through network infrastructure before handover. This replaces expensive over-the-air PANA signaling with efficient network-side credential distribution, achieving pre-authentication without high signaling costs.
Data Source
AI summary
A method and apparatus for authenticating a mobile terminal are provided. A list of potential Network Access Servers (NASs) corresponding to a NAS are maintained in a backend authentication server, authorization information corresponding to each of the potential NASs is transmitted, from the backend authentication server to each of the potential NASs, when the mobile terminal is authenticated via the NAS. The mobile terminal detects whether a new NAS is pre-authenticated, when the mobile terminal moves to a domain of the new NAS, the new NAS detects whether the mobile terminal is pre-authenticated, and the new NAS authenticates the mobile terminal via a Pre-Shared Key (PSK) method, when the mobile terminal and the new NAS are pre-authenticated.


