Authentication Proxy Server Mobility Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile networks, existing technologies face challenges in securely managing mobility signaling messages, particularly when authentication servers do not support MIP registration, leading to potential unauthorized data packet forwarding and lack of cryptographic security for mobility signaling.

Innovation Solution

A method is introduced that involves constructing a radio connection between a mobile subscriber and an access network using an authentication proxy server to authenticate the subscriber and generate a mobility key for cryptographic securing of mobility signaling messages, even when the home network's AAA server does not support MIP registration, by preparing a mobility key if the subscriber identity matches saved identities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an authentication proxy server is introduced to generate mobility keys, then cryptographic security for mobility signaling is improved, but device complexity increases

Engineering Contradiction:
Improvecryptographic securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An authentication proxy server is introduced as an intermediary component between the mobile station and the home agent. This proxy server generates mobility keys locally when the home network's AAA server does not support MIP registration, thereby providing cryptographic security without requiring modifications to the core authentication infrastructure. The proxy acts as a mediator that bridges the gap between legacy AAA servers and MIP security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If mobility key generation is implemented in the authentication proxy server, then compatibility with legacy AAA servers is improved, but the authentication proxy server's functional complexity increases

Engineering Contradiction:
ImprovecompatibilityVSAvoidproxy server complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication proxy server is designed to perform multiple functions: it authenticates mobile stations, generates mobility keys for MIP signaling, and interfaces with legacy AAA servers that do not support MIP registration. By consolidating these diverse functions in a single component, the system achieves broad compatibility without requiring separate specialized servers for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the home agent requests mobility keys from the authentication proxy server, then security for mobile stations in visited networks is improved, but signaling overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The authentication proxy server pre-generates and stores mobility keys for authenticated mobile stations during the initial authentication phase. When the home agent subsequently requests mobility keys, the proxy can quickly retrieve pre-computed keys rather than generating them on-demand, thereby reducing signaling overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8533471B2Method and server for providing mobility key
Publication Date: 2013.09.10 SIEMENS AG
  • US8533471B2 patent drawing
  • US8533471B2 patent drawing
  • US8533471B2 patent drawing

AI summary

After a radio link is established between a mobile subscriber terminal and an access network, to authenticate the subscriber an authentication proxy server of an intermediate network forwards at least one authentication message containing a subscriber identification between the access network and a home network of the subscriber. If authentication is given by an authentication server of the home network, the authentication proxy server of the intermediate network stores the subscriber identification. The home agent receives a registration request message originating from the subscriber terminal and containing a subscriber identification; the home agent transmits a key request message, containing the subscriber identification, for a mobile key to the relevant authentication proxy server. The authentication proxy server provides a mobile key for the home agent, if the subscriber identification contained in the key request message matches one of the subscriber identifications that has been stored by the authentication proxy server.