Subscriber-Specific PMIP Enforcement via Authentication Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional IP protocols in mobile networks face challenges in maintaining continuous connectivity due to IP address changes, leading to interrupted connections, and security issues arise from unauthorized access in mobile radio networks, particularly in WiMax environments where authentication and authorization are complex.

Innovation Solution

Implementing a method for subscriber-specific activation of network-based mobility management (PMIP) using an authentication server that sends an activation attribute (PMIP_ONLY) to enforce network-based mobility management, even when mobile terminals support terminal-based mobility management (CMIP), ensuring complete control over mobility management and security features like confidentiality and authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If terminal-based mobility management (CMIP) is used, then mobile terminals can autonomously manage their own mobility, but network control and security management become difficult

Engineering Contradiction:
Improveautonomous mobility managementVSAvoidnetwork control complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the mobile terminal and the network. This server receives authentication requests from terminals, makes authorization decisions, and sends commands back to terminals. This intermediary structure allows terminals to operate autonomously while maintaining centralized network control and security management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the control parameter from distributed terminal-based management to centralized authentication server-based management. By shifting the decision-making authority to the authentication server through parameter changes in the system architecture, the patent achieves both terminal autonomy and network control.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If network-based mobility management (PMIP) is enforced, then network control and security are improved, but mobile terminals must be continuously adapted

Engineering Contradiction:
Improvenetwork controlVSAvoidterminal adaptation
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent enables mobile terminals to self-configure and self-adapt based on authentication results received from the authentication server. The terminal automatically adjusts its mobility management mode (CMIP or PMIP) according to the authorization decision, eliminating the need for manual configuration and continuous network intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements dynamic adaptability where the terminal's mobility management mode can change based on network conditions and authorization decisions. The system dynamically switches between CMIP and PMIP modes, allowing terminals to adapt to different network environments while maintaining network control.

Inventive Principle:
Principle #15Dynamics

3Reliability

If authentication is required for every network access, then security is improved, but connection establishment time increases

Engineering Contradiction:
ImprovesecurityVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and authorization actions before the mobile terminal actually accesses the network. The authentication server pre-authenticates the terminal and determines the appropriate mobility management mode in advance, so that when the terminal needs to access the network, the authentication is already complete, reducing connection establishment time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous authentication sessions where, after initial authentication, the terminal can perform subsequent network accesses without repeating the full authentication process. The authentication server maintains session information, allowing rapid re-authentication and continuous network access while maintaining security.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8769261B2Subscriber-specific enforcement of proxy-mobile-IP (PMIP) instead of client-mobile-IP (CMIP)
Publication Date: 2014.07.01 SIEMENS AG
  • US8769261B2 patent drawing
  • US8769261B2 patent drawing
  • US8769261B2 patent drawing

AI summary

A method provides subscriber-specific activation of network-based mobility management using an authentication server. According to the method, network-based mobility management is enforced, even if the mobile terminal supports terminal-based mobility management. This gives a network provider complete control over mobility management in his network, preventing configuration problems during the configuration of mobile terminals. In the method, after the successful authentication of a subscriber, the authentication server transmits an authentication confirmation message to an authentication client in an access network. The received authentication confirmation message contains an activation attribute for activating network-based mobility management, if the authentication server does not provide a common mobile key for terminal-based mobility management.