Security Gateway Session Continuity for Mobile IP Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for managing terminal mobility in communication networks often require rerouting traffic to the home node, new IPSec session installation, and centralized protocol message exchanges, leading to potential disruptions and inefficiencies, especially when terminals change IP addresses.

Innovation Solution

The implementation of an Integrated Access Router (IAR) with a Security Gateway that uses the ESP IPSec protocol to maintain seamless and transparent secure access connections across different access points, avoiding the need for rerouting and centralized repositories, and allowing persistent IP addresses to maintain active sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic is rerouted to the home node to maintain IP access session during terminal mobility, then session continuity is improved, but network complexity and routing overhead increase

Engineering Contradiction:
Improvesession continuityVSAvoidrouting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security gateway as an intermediary component that manages IPSec security associations between terminals and the network. This gateway handles the complexity of maintaining secure connections during mobility by centralizing security context management, thereby reducing the routing complexity burden on individual nodes while ensuring session continuity through proper security association maintenance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If new IPSec sessions are installed when terminals move to new access points, then secure connection is ensured, but connection establishment time and overhead increase

Engineering Contradiction:
Improvesecure connectionVSAvoidconnection establishment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing and maintaining security associations at the security gateway before the terminal actually moves to a new access point. The gateway proactively manages the IPSec security contexts, allowing the terminal to move between access points without requiring new security association establishment, thus reducing connection establishment time while maintaining secure connections.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If centralized protocol message exchanges are used for mobility management, then control and authentication are simplified, but network latency and processing overhead increase

Engineering Contradiction:
Improvecontrol simplicityVSAvoidprocessing latency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent enables self-service by allowing the terminal to autonomently manage its mobility and security associations. The terminal can move between access points and maintain its IP address without requiring extensive centralized protocol message exchanges for each mobility event. The security gateway provides support services while the terminal independently handles connection maintenance, reducing processing latency and network overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2272270B1A method for network access, related network and computer program product therefor
Publication Date: 2018.08.22 TELECOM ITALIA SPA
  • EP2272270B1 patent drawingFigure 1~3
  • EP2272270B1 patent drawingFigure 2a~2c

AI summary

A method of providing access of a mobile terminal (MS) to an IP network includes establishing a security association (SA) between the mobile terminal (MS) and a first security gateway (SGWHOME) of a first router (IARHOME) in said plurality of routers. The mobile terminal (MS) is provided access to the IP network via the first router (IARHOME). and the data exchanged between the mobile terminal (MS) and the first router (IARHOME) is encapsulated by using the security association (SA). The security association (SA) is made available to at least one second router (IARVISITED) having a second security gateway (SGWVISITED)- The mobile terminal (MS) is provided access to the IP network via said the second router (IARVISITED). and data exchanged between the mobile terminal (MS) and the second router (IARVISITED) are encapsulated by using the same security association (SA). Establishing the security association (SA) includes assigning a Security Parameter Index (SPI) that identifies univocally the first security gateway (SGWHOME) and the security association (SA). Making the security association (SA) available to the second router (IARVISITED) includes making available to the second router (IARVISITED) the Security Parameter Index (SPI). The second router (IARVISITED) may thus have access to the security association (SA) either by requesting it from the first router (IARHOME) or by identifying it in a set of security associations (SA) sent from the first router (IARHOME) to a set of routers candidate to become the second router (IARVISITED) as result of the mobility of the mobile terminal (MS).