Token-Based Dynamic Key Distribution for Roaming Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication networks face challenges in authenticating mobile devices when they roam into foreign networks, as there is often no prior security association between the mobile device and the network source, making it difficult to establish secure communication.

Innovation Solution

A method is introduced to create a security association between a mobile node and a network source by using encrypted tokens, where a first token is encrypted with a key known to the mobile node and a second token with a key known to a trust authority in the foreign network, allowing the network source to authenticate the mobile node through a chain of trust infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a mobile device roams into a foreign network, then the device can access foreign network services, but the network source cannot authenticate the mobile device due to no prior security association

Engineering Contradiction:
Improveroaming capabilityVSAvoidauthentication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a home network and a chain of trust infrastructure as intermediaries between the mobile device and foreign network source. The home network creates encrypted tokens containing security associations, which are transmitted through the chain of trust to the foreign network, enabling authentication without direct prior association between the mobile device and foreign network source.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The home network performs preliminary authentication and creates security associations with the mobile device before roaming occurs. Encrypted tokens containing these security associations are generated in advance and can be used when the mobile device roams to foreign networks, eliminating the need for real-time authentication setup.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encrypted tokens are transmitted through a chain of trust infrastructure, then security association is established between mobile node and network source, but the complexity of the authentication process increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into distinct components: token creation by the home network, token transmission through the chain of trust infrastructure, and token verification by the foreign network source. Each component handles a specific part of the authentication process, making the overall complex system manageable and modular.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8005224B2Token-based dynamic key distribution method for roaming environments
Publication Date: 2011.08.23 FUTUREWEI TECHNOLOGIES INC
  • US8005224B2 patent drawing
  • US8005224B2 patent drawing
  • US8005224B2 patent drawing

AI summary

A method for establishing a new security association between a mobile node and a network source, the method comprising creating a first token comprising a security association between a network source and a mobile node, the first token being encrypted using a first key known to the mobile node and a first trust authority within a home network associated with the mobile node, and creating a second token comprising the same security association between the network source and the mobile node, the second token being encrypted using a second key known to the first trust authority and a second trust authority associated with the network source, wherein the first token and the second token are sent to the second trust authority using a chain of trust infrastructure.