Security Gateway Session Continuity for Mobile IP Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for managing terminal mobility in communication networks often require rerouting traffic to the home node, new IPSec session installation, and centralized protocol message exchanges, leading to potential disruptions and inefficiencies, especially when terminals change IP addresses.
Innovation Solution
The implementation of an Integrated Access Router (IAR) with a Security Gateway that uses the ESP IPSec protocol to maintain seamless and transparent secure access connections across different access points, avoiding the need for rerouting and centralized repositories, and allowing persistent IP addresses to maintain active sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traffic is rerouted to the home node to maintain IP access session during terminal mobility, then session continuity is improved, but network complexity and routing overhead increase
Solution Approach 1:
The patent introduces a security gateway as an intermediary component that manages IPSec security associations between terminals and the network. This gateway handles the complexity of maintaining secure connections during mobility by centralizing security context management, thereby reducing the routing complexity burden on individual nodes while ensuring session continuity through proper security association maintenance.
2Reliability
If new IPSec sessions are installed when terminals move to new access points, then secure connection is ensured, but connection establishment time and overhead increase
Solution Approach 1:
The patent implements preliminary action by pre-establishing and maintaining security associations at the security gateway before the terminal actually moves to a new access point. The gateway proactively manages the IPSec security contexts, allowing the terminal to move between access points without requiring new security association establishment, thus reducing connection establishment time while maintaining secure connections.
3Ease of operation
If centralized protocol message exchanges are used for mobility management, then control and authentication are simplified, but network latency and processing overhead increase
Solution Approach 1:
The patent enables self-service by allowing the terminal to autonomently manage its mobility and security associations. The terminal can move between access points and maintain its IP address without requiring extensive centralized protocol message exchanges for each mobility event. The security gateway provides support services while the terminal independently handles connection maintenance, reducing processing latency and network overhead.
Data Source
Figure 1~3
Figure 2a~2c
AI summary
A method of providing access of a mobile terminal (MS) to an IP network includes establishing a security association (SA) between the mobile terminal (MS) and a first security gateway (SGWHOME) of a first router (IARHOME) in said plurality of routers. The mobile terminal (MS) is provided access to the IP network via the first router (IARHOME). and the data exchanged between the mobile terminal (MS) and the first router (IARHOME) is encapsulated by using the security association (SA). The security association (SA) is made available to at least one second router (IARVISITED) having a second security gateway (SGWVISITED)- The mobile terminal (MS) is provided access to the IP network via said the second router (IARVISITED). and data exchanged between the mobile terminal (MS) and the second router (IARVISITED) are encapsulated by using the same security association (SA). Establishing the security association (SA) includes assigning a Security Parameter Index (SPI) that identifies univocally the first security gateway (SGWHOME) and the security association (SA). Making the security association (SA) available to the second router (IARVISITED) includes making available to the second router (IARVISITED) the Security Parameter Index (SPI). The second router (IARVISITED) may thus have access to the security association (SA) either by requesting it from the first router (IARHOME) or by identifying it in a set of security associations (SA) sent from the first router (IARHOME) to a set of routers candidate to become the second router (IARVISITED) as result of the mobility of the mobile terminal (MS).