Remote Unit Reauthentication via Key Management Domain
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The EAP Re-authentication Protocol (ERP) currently does not support sharing of re-authentication security context among ER-Servers during UE mobility, leading to unnecessary delays and complexity in UE attachment due to full authentication requirements when moving between different ER-Servers.
Innovation Solution
The introduction of EAP Re-authentication Extensions (ERXs) and the use of key management domains to control sharing of UE's re-authentication security context among TNGFs or TNANs, reducing overhead by using dynamic rIK for integrity protection and avoiding domain-specific root re-authentication key (DSRK) involvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full EAP authentication is performed when UE moves between different ER-Servers, then authentication security is maintained, but attachment delay and network overhead increase
Solution Approach 1:
The authentication process is segmented into two types: full EAP authentication for initial access or after key expiration, and faster reauthentication using reauthentication security context for mobility between ER-Servers. This segmentation allows the system to maintain security while reducing attachment delay by using the appropriate authentication method based on the scenario.
Solution Approach 2:
The reauthentication security context is established during the initial full EAP authentication process and stored in the ER-Server. This preliminary action enables faster reauthentication when the UE moves between ER-Servers, as the security context is already in place and does not require a complete re-authentication process.
2Loss of time
If reauthentication security context is shared among multiple ER-Servers, then handover latency is reduced, but security risk increases due to potential key leakage
Solution Approach 1:
Each ER-Server maintains its own reauthentication security context independently, but these contexts are shared across multiple ER-Servers within the same key management domain. This local quality approach ensures that security contexts are available where needed while maintaining proper security boundaries.
Solution Approach 2:
The system uses dynamic reauthentication integrity keys (rIK) that are derived from the reauthentication security context and key management domain name. This parameter change approach allows the system to maintain security through dynamic key management while enabling context sharing for low-latency handovers.
3Device complexity
If static reauthentication integrity key (rIK) is used for integrity protection, then implementation is simple, but security is compromised due to potential leakage
Solution Approach 1:
The system transitions from static rIK to dynamic rIK that are derived on-demand during reauthentication based on the reauthentication security context and key management domain name. This dynamic approach enhances security by ensuring that the integrity key is fresh and has not been leaked, while the derivation process remains relatively simple.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for supporting remote unit reauthentication. One apparatus apparatus includes a processor and a transceiver that sends a first authentication message to a network function in a mobile communication network and receives a second authentication message from the network function in response to the first authentication message. Here, the first authentication message contains an indicator that the apparatus supports EAP Reauthentication Protocol and the second authentication message contains a key management domain name indicating a group of network functions that can share reauthentication security context. The processor derives reauthentication security context in response to successful authentication with the mobile communication network and locally stores the received key management domain name and the derived reauthentication security context for subsequent reauthentication with the mobile communication network.


