Session Handover Between Incompatible Authentication Nodes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication systems face challenges in implementing seamless session handovers between devices with different authentication key generation functions, particularly in networks like 3GPP, where devices without SIM cards or incompatible authentication methods fail to authenticate, leading to failed session transfers.
Innovation Solution
The system enables session handovers by using authentication information from the first node to authenticate with an authentication server of a different network, allowing devices with different key generation functions to transfer sessions through EAP authentication, even if they cannot directly authenticate with the target network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a device without SIM card or with incompatible authentication method attempts to authenticate directly with the target network, then authentication fails, but session handover cannot be completed
Solution Approach 1:
The source network acts as an intermediary by performing authentication on behalf of the target device. The source network uses the target device's authentication information to communicate with the authentication server, enabling the target device to access the target network without direct authentication capability.
Solution Approach 2:
The authentication process is segmented into two independent parts: authentication information management (handled by source network using target device's credentials) and session handover execution (performed by target device). This separation allows devices without authentication capabilities to still complete handover.
2Adaptability or versatility
If session handover is implemented between devices with different key generation functions, then network mobility is enhanced, but authentication compatibility becomes problematic
Solution Approach 1:
The source network performs multiple functions: it manages the target device's authentication information, performs authentication with the authentication server on behalf of the target device, and coordinates the session handover process. This multi-functionality enables compatibility between devices with different authentication capabilities.
Solution Approach 2:
The source network uses copies of the target device's authentication information (stored in the source network) to perform authentication with the authentication server. This copying mechanism allows the target device to handover sessions without needing its own authentication credentials.
3Reliability
If direct authentication is required for session transfer, then security is maintained, but devices without SIM cards cannot transfer sessions
Solution Approach 1:
The source network serves as a secure intermediary that protects the authentication process. It securely stores and uses the target device's authentication information to communicate with the authentication server, maintaining security while enabling devices without SIM cards to complete handover.
Solution Approach 2:
The authentication information of the target device is preliminarily stored in the source network before handover occurs. This preliminary storage enables the source network to perform authentication on behalf of the target device when needed, ensuring both security and accessibility.
Data Source
AI summary
Disclosed is a technique to enable a session handover between devices with different key generation functions in an authentication protocol. According to the technique, when a session where a UE (200) receives contents from a contents server (700) is to be handed over to a target node (300), the UE firstly transfers information (session HO information) necessary to the session handover to the target node (Step S1001). The target node performs authentication processing with an authentication server (600) of the network to which the UE is connected and notifies the authentication server of the session HO information transferred from the UE (Step S1003). The authentication server performs authentication for the session handover based on the session HO information, and when the authentication succeeds, the session is handed over from the contents server to the target node, and the contents are distributed to the target node (Step S1005).


