Media-independent Pre-authentication Framework for Seamless Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobility management protocols face challenges in providing seamless handovers across different types of access networks, especially across IP subnets and administrative domains, with issues such as tight coupling with specific protocols, lack of support for handovers without pre-established security associations, and inability to handle multi-interface terminals efficiently.

Innovation Solution

The introduction of a media-independent pre-authentication (MPA) mechanism that allows mobile nodes to perform pre-authentication and pre-configuration with candidate target networks, establishing a secure proactive handover tunnel before attaching to the new network, enabling seamless handovers across various link-layer technologies and mobility management protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional mobility management protocols are used for handover, then security associations must be pre-established between administrative domains, but this increases device complexity and limits adaptability to different network scenarios

Engineering Contradiction:
Improvehandover securityVSAvoidpre-established security associations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs pre-authentication and pre-configuration actions before the actual handover occurs. The mobile node discovers candidate target networks, performs authentication, and establishes IP addresses in advance, so that when handover is needed, the security and configuration are already in place, eliminating the need for complex runtime security association establishment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a tunnel mechanism as an intermediary between the mobile node and the correspondent node during handover. The tunnel allows packets to be forwarded from the old access router to the new access router, providing a secure and simplified path that avoids complex direct security associations between administrative domains

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If authentication and configuration are performed after link-layer handover, then handover speed is faster, but packet loss increases during the transition

Engineering Contradiction:
Improvehandover speedVSAvoidpacket loss
Core Design Contradiction:
SpeedVSLoss of substance

Solution Approach 1:

The patent performs authentication, IP address acquisition, and configuration actions before the link-layer handover completes. By the time the mobile node switches to the new access point, all networking parameters are already configured, allowing immediate data transmission without waiting for post-handover setup, thus preventing packet loss while maintaining fast handover

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuous useful action by establishing a tunnel that can forward packets during the handover transition. The tunnel maintains the data path continuity from the correspondent node through the old access router to the new access router, ensuring no packets are lost during the brief transition period when the mobile node is attaching to the new network

Inventive Principle:
Principle #20Continuity of useful action

3Ease of manufacture

If mobility management is tightly coupled with specific protocols, then implementation is simpler, but adaptability to different link-layer technologies and mobility management protocols is reduced

Engineering Contradiction:
Improveimplementation simplicityVSAvoidprotocol independence
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal pre-authentication framework that works with multiple link-layer technologies (WiFi, WiMAX, cellular) and mobility management protocols (Mobile IP, SIP). The framework uses standardized discovery mechanisms, authentication protocols, and tunnel establishment procedures that can adapt to different underlying technologies without requiring protocol-specific implementations, achieving both simplicity and versatility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the mobility management functionality into distinct modular components: network discovery, pre-authentication, pre-configuration, tunnel establishment, and handover execution. Each component is independently designed and can be configured for different technologies, allowing the system to maintain simple implementations for each function while providing broad adaptability through composition

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7813319B2Framework of media-independent pre-authentication
Publication Date: 2010.10.12 TELCORDIA TECHNOLOGIES INC
  • US7813319B2 patent drawing
  • US7813319B2 patent drawing
  • US7813319B2 patent drawing

AI summary

This application describes, among other things, a framework of Media-independent Pre-Authentication (MPA), a new handover optimization mechanism that has a potential to address issues on existing mobility management protocols and mobility optimization mechanisms. MPA is a mobile-assisted, secure handover optimization scheme that works over any link-layer and with any mobility management protocol. This application also shows, among other things, an initial implementation of MPA in our testbed and some performance results to show how existing protocols could be leveraged to realize the functionalities of MPA.