Session Handover Between Incompatible Authentication Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems face challenges in implementing seamless session handovers between devices with different authentication key generation functions, particularly in networks like 3GPP, where devices without SIM cards or incompatible authentication methods fail to authenticate, leading to failed session transfers.

Innovation Solution

The system enables session handovers by using authentication information from the first node to authenticate with an authentication server of a different network, allowing devices with different key generation functions to transfer sessions through EAP authentication, even if they cannot directly authenticate with the target network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a device without SIM card or with incompatible authentication method attempts to authenticate directly with the target network, then authentication fails, but session handover cannot be completed

Engineering Contradiction:
Improveauthentication success rateVSAvoidsession handover capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The source network acts as an intermediary by performing authentication on behalf of the target device. The source network uses the target device's authentication information to communicate with the authentication server, enabling the target device to access the target network without direct authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into two independent parts: authentication information management (handled by source network using target device's credentials) and session handover execution (performed by target device). This separation allows devices without authentication capabilities to still complete handover.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If session handover is implemented between devices with different key generation functions, then network mobility is enhanced, but authentication compatibility becomes problematic

Engineering Contradiction:
Improvesession handover capabilityVSAvoidauthentication compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The source network performs multiple functions: it manages the target device's authentication information, performs authentication with the authentication server on behalf of the target device, and coordinates the session handover process. This multi-functionality enables compatibility between devices with different authentication capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The source network uses copies of the target device's authentication information (stored in the source network) to perform authentication with the authentication server. This copying mechanism allows the target device to handover sessions without needing its own authentication credentials.

Inventive Principle:
Principle #26Copying

3Reliability

If direct authentication is required for session transfer, then security is maintained, but devices without SIM cards cannot transfer sessions

Engineering Contradiction:
Improvesession transfer securityVSAvoidsession handover accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The source network serves as a secure intermediary that protects the authentication process. It securely stores and uses the target device's authentication information to communicate with the authentication server, maintaining security while enabling devices without SIM cards to complete handover.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication information of the target device is preliminarily stored in the source network before handover occurs. This preliminary storage enables the source network to perform authentication on behalf of the target device when needed, ensuring both security and accessibility.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8964694B2Communication system, communication processing device and authentication processing device
Publication Date: 2015.02.24 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US8964694B2 patent drawing
  • US8964694B2 patent drawing
  • US8964694B2 patent drawing

AI summary

Disclosed is a technique to enable a session handover between devices with different key generation functions in an authentication protocol. According to the technique, when a session where a UE (200) receives contents from a contents server (700) is to be handed over to a target node (300), the UE firstly transfers information (session HO information) necessary to the session handover to the target node (Step S1001). The target node performs authentication processing with an authentication server (600) of the network to which the UE is connected and notifies the authentication server of the session HO information transferred from the UE (Step S1003). The authentication server performs authentication for the session handover based on the session HO information, and when the authentication succeeds, the session is handed over from the contents server to the target node, and the contents are distributed to the target node (Step S1005).