Dynamic foreign agent-home agent security association allocation for IP mobility systems
22 claims: 5 independent, 17 dependent
- 1ホーム・エージェントとホーム・ネットワークAAAサーバとを有するホーム・ネットワークと、 外部エージェントを有する外部ネットワークと、 ホーム・エージェント-外部エージェント対を求める特定のセキュリティ・アソシエーション要求を前記外部エージェントから受け取った後、前記ホーム・ネットワークAAAサーバからのセキュリティ・パラメータおよびSPIインデックス値の動的割当てに基づいて前記ホーム・エージェントと前記外部エージェントの間に確立されるセキュリティ・アソシエーションとを備える通信システムであって、前記セキュリティ・アソシエーション要求が、前記外部エージェントによって移動ノードから登録要求が受け取られた後に開始され、前記外部エージェントによって受け取られた前記登録要求が、前記外部エージェントと前記ホーム・エージェントの間の前記セキュリティ・アソシエーションが確立された後に前記ホーム・エージェントに転送され、前記ホーム・ネットワークAAAサーバが、前記外部エージェントが特定のホーム・エージェント-外部エージェント対を求めるセキュリティ・アソシエーションを要求するたびに前記セキュリティ・パラメータおよびSPIインデックス値を動的に割り当てる、通信システム。
- 2前記ホーム・ネットワークAAAサーバが、ホーム・エージェント-外部エージェント対の既存のセキュリティ・アソシエーションが存在している場合でも、前記外部エージェントがその特定のホーム・エージェント-外部エージェント対のセキュリティ・アソシエーションを要求するたびに前記セキュリティ・パラメータおよびSPIインデックス値を動的に割り当てる、請求項1に記載の通信システム。
- 3古いSPIインデックス値が、前記ホーム・ネットワークAAAサーバによって発行された前記動的に割り当てられたSPIインデックス値に一致しない場合は、それらの値が無効とみなされる、請求項1に記載の通信システム。
- 4動的に割り当てることができるセキュリティ・パラメータが、外部エージェント-ホーム・エージェント共有秘密鍵または公開/秘密鍵対を含む、請求項1に記載の通信システム。
- 5動的に割り当てることができるセキュリティ・パラメータが、認証アルゴリズムおよびモードを含む、請求項1に記載の通信システム。
- 6動的に割り当てることができるセキュリティ・パラメータが、外部エージェント-ホーム・エージェント秘密鍵有効期間を含む、請求項1に記載の通信システム。
- 7移動ノードと、ホーム・ネットワーク上のホーム・エージェントとの間に安全な通信経路を確立するための方法であって、 外部ネットワーク上に位置する前記移動ノードから前記外部ネットワーク上の外部エージェントで登録要求を受け取るステップであって、前記登録要求が、前記移動ノードと、前記ホーム・ネットワーク上に位置する前記ホーム・エージェントとの間の通信経路を確立するための気付アドレッシング情報を含む、ステップと、 特定の外部エージェント-ホーム・エージェント対を求めるセキュリティ・アソシエーション要求と共に、前記ホーム・ネットワーク上に位置するホーム・ネットワークAAAサーバに前記外部エージェントからのアクセス要求を送信するステップであって、前記ホーム・ネットワークAAAサーバが、前記セキュリティ・アソシエーション要求をサポートするためのセキュリティ・パラメータを動的に割り当てる、ステップと、 前記ホーム・ネットワークAAAサーバから、前記ホーム・ネットワークAAAサーバによって生成された前記動的に割り当てられたセキュリティ・パラメータ情報を含むアクセス応答を前記外部エージェントで受け取るステップと、 前記外部エージェントによって受け取られた前記セキュリティ・パラメータの選択された部分を含む前記登録要求を前記外部エージェントから前記ホーム・エージェントに送信するステップであって、前記ホーム・エージェントが、前記登録要求を受け取った後、前記動的に割り当てられたセキュリティ・パラメータ情報を別個に前記ホーム・ネットワークAAAサーバから受け取る、ステップと、 前記外部エージェント-ホーム・エージェント・セキュリティ・アソシエーション情報の確認の後、前記外部エージェントで前記ホーム・エージェントから登録応答を受け取るステップであって、前記登録応答が、前記ホーム・エージェントと前記移動ノードの間の前記通信経路を確立するために前記移動ノードに提供される、ステップとを備える方法。
- 8前記ホーム・ネットワークAAAサーバが、前記外部エージェントが特定のホーム・エージェント-外部エージェント対を求めるセキュリティ・アソシエーションを要求するたびに前記セキュリティ・パラメータ情報を動的に割り当てる、請求項7に記載の方法。
- 9前記ホーム・ネットワークAAAサーバが、前記外部エージェントが特定のホーム・エージェント-外部エージェント対を求めるセキュリティ・アソシエーションを要求するたびに、SPIインデックス値を含む前記セキュリティ・パラメータ情報を動的に割り当てる、請求項7に記載の方法。
- 10古いSPIインデックス値が、前記ホーム・ネットワークAAAサーバによって発行された前記動的に割り当てられたSPIインデックス値に一致しない場合は、それらの値が無効とみなされる、請求項9に記載の方法。
- 11前記ホーム・ネットワークAAAサーバが、ホーム・エージェント-外部エージェント対の既存のセキュリティ・アソシエーションが存在している場合でも、前記外部エージェントがその特定のホーム・エージェント-外部エージェント対のセキュリティ・アソシエーションを要求するたびに前記セキュリティ・パラメータを動的に割り当てる、請求項7に記載の方法。
- 12動的に割り当てることができるセキュリティ・パラメータが、外部エージェント-ホーム・エージェント共有秘密鍵または公開/秘密鍵対を含む、請求項7に記載の方法。
- 13動的に割り当てることができるセキュリティ・パラメータが、認証アルゴリズムおよびモードを含む、請求項7に記載の方法。
- 14動的に割り当てることができるセキュリティ・パラメータが、外部エージェント-ホーム・エージェント秘密鍵有効期間を含む、請求項7に記載の方法。
- 15ホーム・エージェントとホーム・ネットワークAAAサーバ・コンピュータとを有するホーム・ネットワークと、 外部エージェントを有する外部ネットワークと、 ホーム・エージェント-外部エージェント対を求める特定のセキュリティ・アソシエーション要求を前記外部エージェントから受け取った後、前記ホーム・ネットワークAAAサーバ・コンピュータからのセキュリティ・パラメータおよびSPIインデックス値の動的割当てに基づいて前記ホーム・エージェントと前記外部エージェントの間に確立されるセキュリティ・アソシエーションとを備える通信システムであって、前記セキュリティ・アソシエーション要求が、前記外部エージェントによって移動ノードから登録要求が受け取られた後に開始される、通信システム。
- 16前記外部エージェントによって受け取られた前記登録要求が、前記外部エージェントと前記ホーム・エージェントの間に前記セキュリティ・アソシエーションが確立された後に前記ホーム・エージェントに転送される、請求項15に記載の通信システム。
- 17前記ホーム・ネットワークAAAサーバが、前記外部エージェントが特定のホーム・エージェント-外部エージェント対を求めるセキュリティ・アソシエーションを要求するたびに前記セキュリティ・パラメータおよびSPIインデックス値を動的に割り当てる、請求項15に記載の通信システム。
- 18古いSPIインデックス値が、前記ホーム・ネットワークAAAサーバによって発行された前記動的に割り当てられたSPIインデックス値に一致しない場合は、それらの値が無効とみなされる、請求項17に記載の通信システム。
- 19前記ホーム・ネットワークAAAサーバが、ホーム・エージェント-外部エージェント対の既存のセキュリティ・アソシエーションが存在している場合でも、前記外部エージェントがその特定のホーム・エージェント-外部エージェント対のセキュリティ・アソシエーションを要求するたびに前記セキュリティ・パラメータおよびSPIインデックス値を動的に割り当てる、請求項15に記載の通信システム。
- 20動的に割り当てることができるセキュリティ・パラメータが、外部エージェント-ホーム・エージェント共有秘密鍵または公開/秘密鍵対を含む、請求項15に記載の通信システム。
- 21動的に割り当てることができるセキュリティ・パラメータが、認証アルゴリズムおよびモードを含む、請求項15に記載の通信システム。
- 22動的に割り当てることができるセキュリティ・パラメータが、外部エージェント-ホーム・エージェント秘密鍵有効期間を含む、請求項15に記載の通信システム。
Independent claims22
51 paragraphs, as filed
Related application data This application relates to provisional patent application No. 60 / 908,472 filed on March 28, 2007 and No. 60 / 916,866 filed on May 9, 2007 in 35 USC 119 (e). Claim the priority of these prior applications under. These provisional patent applications are also incorporated into this practical patent application by reference.
Systems and methods for any IP-based system, including home networks, external networks, and IP-based mobile communication systems with mobile nodes.
IP-based mobile systems include at least one mobile node within a wireless communication system. The term "mobile node" includes a mobile communication device, and a communication system has a home network and an external network in addition to the mobile node. Mobile nodes can change their point of connection to the Internet through these other networks, but mobile nodes are always associated with a single home network for IP addressing. A home network has a home agent, an external network has an external agent, and both of these agents control the routing of information packets that enter and leave the network.
Mobile nodes, home agents, and external agents may be referred to by other names that depend on the terminology used in any particular network configuration or communication system. For example, a "mobile node" is wireless so that it can be experienced by mobile terminals of different types and models ("mobile phones") with different features and functionality such as Internet access, email, and messaging services. Includes PCs that have cable-type connectivity to networks (eg, telephone lines (twisted pair), Ethernet cables, optical cables, etc.), as well as direct wireless connectivity to cellular networks. Home agents are sometimes referred to as home agents, home mobility managers, and home location registers, and external agents are external agents, serving mobility managers, and location locations. Visited Location Register and Visiting Serving Sometimes called Entity). The terms mobile node, home agent and external agent may include, but are not limited to, other mobile communication or monitoring routing equipment located in the home or external network.
The mobile node keeps informing the home agent about its current location by registering the "notice address" with the home agent. In essence, the awareness address represents the current external network where the mobile node is located. If the home agent receives an information packet addressed to a mobile node while the mobile node is located on the external network, it sends the information packet to the mobile node's current location on the external network using an applicable awareness address. To do.
The external agent is involved in notifying the home agent of the current awareness address of the mobile node. The external agent receives the information packet for the mobile node even after the information packet has been forwarded by the home agent. In addition, the external agent acts as a default router for outgoing information packets generated by mobile nodes while connected to the external network.
External agents and home agents periodically broadcast agent advertisements to all nodes on the local network associated with the agent. Agent ads are messages from agents on the network that can be issued based on the Mobile IP Protocol (RFC 2002) or any other type of communication protocol. This advertisement should contain the information needed to uniquely identify the mobility agent (eg home agent, external agent, etc.) for the mobile node. The mobile node inspects the agent advertisement to determine if the mobile node is connected to the home or external network.
If the mobile node is located on its home network, information packets are routed to the mobile node according to standard addressing and routing schemes. However, when the mobile node is located in the external network, it obtains appropriate information from the agent advertisement and sends a registration request message to the home agent via the external agent. The registration request message contains the noticed address of the mobile node.
The registered awareness address identifies the external network where the mobile node is located, and the home agent uses this registered awareness address to forward information packets to the external network for subsequent transfers to the mobile node. To do. A registration response message may be sent by the home agent to the mobile node to confirm that the registration process has completed successfully.
Upon moving to the new network, the mobile node detects the movement of the mobile node by receiving a router advertisement message from the new router or by exceeding the time interval for receiving the expected router advertisement message from the linked router. The mobile node can also periodically send router solicitation messages received by routers on the external network and initiate transmission of router advertising messages received by mobile nodes.
The router advertisement message contains network prefix information used to form a care address for routing information packets from the home network to mobile nodes on the external network. A registration request or Binding Update message (BU) is used to register a notice address with the home agent and any active corresponding node that communicates with the mobile node. The new registration request includes the awareness address, the home address, and the validity period of the binding. A Binding Acknowledgment message (BA) is sent in response to a request or binding update message to accept or reject the binding update as an authentication step. The router on the network maintains an association between the mobile node's awareness address and the home IP address on the data table to ensure that information packets can be routed to the mobile node connected to the external network.
In an IP-based mobile communication system, a mobile node changes its connection point to the network while maintaining network connectivity. The Mobile IP Protocol (RFC 2002) assumes that mobile IP communication with mobile nodes is performed on a single management domain or network controlled by one administrator. However, if the mobile node moves out of its home management domain, the mobile node may need to communicate over multiple external networks in order to maintain network connectivity with its home network. While connected to an external network controlled by another management domain, the network server must authenticate, authorize, and collect accounting information for services given to mobile nodes. These certification, authorization and accounting activities are referred to as "AAA" activities.
Authentication is the process of proving the identity of someone claimed, and security systems on mobile IP networks often require the identification of system users before allowing the requested activity. The AAA server on the network authenticates the identities of authorized users and allows the requested activity of the mobile node. In addition, the AAA server also supports accounting features, including tracking usage and fees for the use of transmission links between management domains.
Remote Authentication Dial In User Service (RADIUS) is one of the widely used protocols for AAA. The RADIUS protocol defines the message formats and data required for AAA that can be used on virtually any packet-based communication system. Functionally, RADIUS can perform client-server operations, network security, authentication, and accounting using standard information encoding with the UDP transmission protocol. RADIUS AAA server computers are widely deployed on wireless networks using the RADIUS protocol to perform AAA functions.
Another feature for AAA servers is to support secure information packet transmission by storing and allocating security associations. A security association refers to the encryption protocol, nonce, and key required to specify and support the transmission of information packets between two nodes in a secure manner. A security association is a collection of security contexts that exist between nodes that can be applied to information packets exchanged between nodes. Each context indicates an authentication algorithm and mode, a shared key or proper public / private key pair, and a replay protection style.
Extensions are defined in the IP protocol, which can be used in similar protocols to support the transmission of variable amounts of data within information packets. It contains mobile node, router and network address information. The IP extension mechanism allows proper addressing and routing information to be carried by arbitrary information packets without restrictions on dedicated message types such as discovery, notification, control and routing information packet formats.
Common extended formats include the Type-Length-Value format. Type data field (T) 1 occupies the first 8 bits (1 octet) of a typical extension. The value of this data field specifies the type of extension. The length data field (L) 2 occupies the next 8 bits of the extension, and the value assigned is the length of the value field (V) 3 in the octet. Value data field 3 occupies the remaining bits of a general extension as specified by type 1 and length 2 data values.
Some functionality of mobile IPv4 requires an external agent to add specific information to the registration request RRQ received from the mobile node before forwarding the registration request RRQ to the home agent. This additional information should be protected from public disclosure, which requires the external agent to establish a security association with the home agent before sending the RRQ to the home agent.
External Agent-The Home Agent Authentication Extension (AE) is an optional extension that can be used to support secure communication between an external network and a home network. To use the FA-HA Authentication Extension (AE), a security association must exist between the external agent FA and the home agent HA. To establish a security association between the external agent and the home agent to support FA-HA Authentication Extension (AE), the external agent establishes a security association between the external agent and the home agent. The FA-HA access request message must be able to dynamically assign security association parameters (eg FA-HA private key, hash function, hash function mode, etc.).
External agents and home agents also use the Security Parameter Index (SPI) to index security associations, and external agents and home agents are between external agents and home agents. Sends the IP address of the mobile node as an index for the security association of. This FA-HA Security Association assignment is RFC It is outside the scope of 2002 (3344) and currently does not have the ability to allocate the support information required for the FA-HA Security Association. It is one object of the present invention. Another objective is to support the dynamic allocation of parameters used in the FA-HA Security Association, along with variable combinations and extensions of previously statically preconfigured parameters. There is a method proposed in the 3GPP2 standard for dynamically assigning a single private key value using a AAA server, but this proposal does not maintain simultaneity between the external agent and the home agent. It does not allow dynamic assignment of other required parameters or security parameter index values.
The present invention uses the AAA infrastructure to dynamically assign the various parameters needed to establish a security association between an external agent and a home agent. The various parameters that can be assigned in the present invention include the FA-HA shared secret or public / private key pair, authentication algorithm and mode, FA-HA private key lifetime, and security parameter index or security index value. Including. The present invention can also help ensure that external agents and home agents remain synchronized with respect to security associations.
The present invention is a central entity that dynamically generates and distributes selected security association parameters needed to support security associations between external agents and home agents based on requests from external agents. Use AAA server. The AAA server can also dynamically assign a unique SPI value to the external agent and home agent pair. After dynamically assigning the required parameters and establishing the FA-HA security association, the external agent can forward the initial registration request from the mobile node to the home agent on the home network.
The object and features of the present invention will be more easily understood from the following detailed description and the appended claims when read in conjunction with the accompanying drawings. In the drawings, the same numbers represent similar elements.
<figref num="1">It is a figure which shows the mobile IP-based communication system.</figref><figref num="2">It is a figure of the message sequence used in this invention.</figref>
Figure 1 shows the overall architecture of an IP-based mobile system with mobile nodes 64, home network 10 and external network 40. As shown in FIG. 1, the home network 10 and the external network 40 are coupled to the Internet represented by the cloud 35. The home network 10 has a central bus line 20 coupled to the home agent 28 via a communication link 24. The bus line 20 is coupled to the AAA server 17 via the communication link 22. The home network 10 is coupled to the Internet 35 via a communication link 30. A communication link is any connection between two or more nodes on a network, or users within a network or management domain.
The external network 40 has a central bus line 50 coupled to an external agent 58 via a communication link 54. Bus line 50 is coupled to AAA external network server 47 via communication link 52. The external network 40 is coupled to the Internet 35 via a communication link 37. The mobile node 64 is shown electronically coupled to the external network 40 via the wireless communication link 66 of the transceiver 60. The transceiver 60 is coupled to the external network 40 via a communication link 62. The mobile node 64 can communicate with any transceiver or access network coupled to the external network 40.
The terms home agent and external agent can be as defined in the Mobile IP Protocol (RFC 2002), but these agents are not limited to a single protocol or system. In fact, in this application, the term home agent is the home mobility manager, home location register, home serving entity, or other on home network 10 responsible for managing mobility-related functions of mobile node 64. Can point to any agent in. Similarly, in this application, the term external agent is responsible for managing the serving mobility manager, the area location register, the area service entity, or the mobility-related functions of mobile node 64, or any other on the external network 40. Can point to any agent.
In the mobile IP communication system shown in FIG. 1, mobile node 64 is identified by a persistent IP address. While mobile node 64 is attached to its home network 10, mobile node 64 receives information packets like any other fixed node on home network 10. When on the move, the mobile node 64 can also be itself located within the external network 40. When located within the external network 40, the home network 10 sends data communication to the mobile node 64 by "tunneling" the communication to the external network 40.
The mobile node 64 keeps informing the home agent 28 of its current location or external network association by registering a notice address with the home agent 28. In essence, the awareness address represents the external network 40 where the mobile node 64 is currently located. If the home agent 28 receives an information packet destined for the mobile node 64 while the mobile node 64 is located within the external network 40, the home agent 28 sends the information packet to the external network 40 for subsequent transmission to the mobile node 64. "Tunneling".
External agent 58 is involved in notifying home agent 28 of the current awareness address of mobile node 64. The external agent 58 still receives the information packet for the mobile node 64 after the information packet has been forwarded by the home agent 28 to the external agent 58. In addition, the external agent 58 acts as the default router for outgoing information packets generated by mobile node 64 while connected to the external network 40.
Mobile node 64 is involved in notifying the home agent 28 of the current awareness address. When the mobile node 64 is located in the external network 40, the mobile node 64 obtains appropriate information about the addresses of the external network 40 and / or the external agent 58 from the agent advertisement. After retrieving this information, the mobile node 64 sends a registration request to the external agent 58, which prepares the registration request message for forwarding to the home agent 28.
The mobile IP protocol requires the mobile node to register a noticed address with the home agent 28 on the home network 10 after moving to the new external network 40. As part of the registration process, mobile node 64 issues a registration request in response to launches on the external network 40 or reception of agent advertisements. The registration request is sent to the home agent 28 on the home network 40, but only after a security association has been established between the external agent 58 and the home agent 28.
After the security association is established, a registration request message containing the care-of address of mobile node 64 may be sent to the home agent 28. A registration response is issued by the home agent 28 to notify that the registration request has been received, confirm receipt of the awareness address of mobile node 64, and indicate that the registration process is complete. The awareness address identifies the external network 40 where the mobile node 64 is located, and the home agent 28 uses this awareness address to tunnel information packets to the external network 40 for subsequent forwarding to the mobile node 64. To do.
All communications destined for mobile node 64 are routed to the mobile node's home network 10 according to normal IP protocols. After registration is complete, Home Agent 28 receives this communication and "tunnels" the message to mobile node 64 on the external network 40. The external agent 58 accepts the re-directed communication and delivers the information packet to the mobile node 64 via the transceiver 60. In this way, information packets destined for mobile node 64 at its normal address on home network 10 are redirected, i.e. forwarded, to mobile node 64 on external network 40.
Without a security association, the above information would be sent in the public domain. However, sending such information in the public domain without a security association could expose authorized users to the following types of attacks: (1) Hostile nodes divert information packets: Security theft to hijack network sessions from mobile nodes by, (2) spoofing where authorized user identification is used in an unauthorized manner to gain access to the network, and (3) authorized Intercepting and stealing information during a session with a user. The present invention prevents this from happening by dynamically establishing security association parameters before sending information from the external agent 58 to the home agent 28.
AAA server AAA server 17 provides authentication and authorization services to users and mobile nodes 64 on home network 10 when connected to external network 40. The present invention uses the AAA server 17 and its surrounding infrastructure to dynamically assign the various parameters needed to establish a security association between the external agent 58 and the home agent 28.
The AAA server 17 is the central entity of the present invention, and the AAA server 17 establishes a security association between the external agent 58 and the home agent 28 before the registration request is sent by the external agent 58 to the home agent 28. Dynamically generate and distribute the selected parameters needed to establish. The various parameters that can be assigned in the present invention are the FA-HA shared secret or public / private key pair, authentication algorithm and mode, FA-HA private key lifetime, response protection mechanism (if required), security. Includes a parameter index (SPI) or security index value, as well as any other required parameters that may be defined in the future.
The Security Parameter Index (SPI) identifies the security context between a pair of nodes available in the Mobility Security Association. Each security context specified indicates the authentication algorithm and mode, public or private key (private key), and response protection style. SPI is found in all authentication extensions and must be used to authenticate the identity of mobile nodes. SPI specifies security protocols (algorithms and keys) for calculating authentication values.
The present invention is a central entity for dynamically generating and distributing selected security association parameters required to support security associations between external agents and home agents based on requests from external agents. Use the AAA server as. The AAA server can also dynamically assign a unique SPI value to the external agent and home agent pair. After dynamically assigning the required parameters and establishing the FA-HA security association, the external agent forwards the initial registration request from the mobile node to that home agent on the home network.
AAA server 17 maintains the state of the newly generated security association and the SPI value for the FA-HA pair. AAA server 17 may be a RADIUS AAA server, which handles RADIUS access requests from external agent 58, dynamically generates the parameters needed to establish a security association, and external agent. Prior to the transfer of the registration request to the home agent 28 by 58, those parameters can be returned to the external agent 58 in a RADIUS access message.
The present invention also helps ensure that the external agent and the home agent maintain a synchronized security association. The present invention is that whenever an external agent 58 requests access and a security association with a designated home agent 28, the security association already exists or the existing security association has not ended. The AAA server 17 still achieves this goal by requiring it to generate a new Security Parameter Index (SPI) for its security association. A new security association is dynamically established using this requirement to generate a new security parameter index (SPI) each time a new request for a security association that specifies a particular home agent 28 occurs. It can be shown that the home agent 28 must obtain new security association parameters from the AAA server 17 in order to continue communicating with the mobile node 64 via the external agent 58.
If the external agent 58 specifies an FA-HA pair that requires the establishment of a security association and this dynamic allocation, the requirement that new security parameter generation or SPI value allocation be performed is the external agent 58. Also occurs when requests a security association and the access request contains an old SPI value. The AAA server 17, which is the control entity that dynamically assigns security parameter values, issues a new security parameter value each time an external agent 58 requests a security association in an access request message for the specified home agent 28. Must be assigned. After providing security association information to the external agent 58, the external agent communicates with the home agent 28, which is dynamically assigned and previously sent to the external agent 58. Query AAA server 17 for security parameter information. When AAA server 17 receives a request from home agent 28 for a specific FA-HA security association with a specific valid SPI value (received from external agent 58), it receives the specified SPI index value and the specified SPI index value. A security association parameter containing the FA-HA private key associated with the specified FA-HA pair must be returned to the home agent 28.
When receiving a request from the home agent 28 for a security association with an invalid SPI value, the AAA server 17 must return a deny message or an indication of the invalid SPI to the home agent 28. Response messages that fail or are rejected cannot be assigned or communicated with dynamically assigned security association parameters. When new security association parameters are dynamically assigned by AAA server 17, the old SPI and security association parameters must be ignored, but AAA server 17 has old security association parameters and new security associations. Can have the ability to store old security association parameters to check for parameter conflicts. The old security parameters and index values can also be useful for retrieving new security parameters and index values from AAA server 17. The most recently generated security parameters and SPI index values support a security association between external agent 58 and home agent 28 when stored.
The only exception to the requirement to dynamically assign new security parameters and new SPI index values is when home agent 28 is dynamically assigned (not specified) in an access request message sent by external agent 58. .. This situation occurs when mobile node 64 sends a registration request message to external agent 58 without identifying the address of home agent 28. In this case, the external agent 58 may not know the identity or address of the home agent 28 when making its access request to the home network AAA server 17. In that case, the external agent 58 can ask the AAA server 17 about the home agent 28 and ask for the security context of the external agent-home agent pair. In response to the information request, AAA server 17 sends a new allocation of security association parameters and a new SPI index value to the external agent 58 if there was no previous allocation. If there was a previous allocation for the HA and SA security association, the previously allocated SPI index value is returned to the FA.
Message ordering of the present invention FIG. 2 is a message flowchart according to the present invention. The Link Layer Set Up message (SU) sequence 305 is communicated between the mobile node 64 and the external agent (FA) 58. After communicating with the external agent 58 via messaging 305, the mobile node 64 sends a registration request message (RRQ: Registration Request Message) to the external agent 58 with message 315. This registration request has the awareness address required for the home agent 28 to forward the information packet to the mobile node 64.
Before sending the registration request message on the home agent 28, the external agent communicates with the H-AAA server 17 on the home network 10 with message 320. Communication 320 to the H-AAA server 17 is an access request (RSA) requesting the establishment of a security association between the external agent 58 and the home agent 28.<sub>1</sub>). Access request (RSA)<sub>1</sub>) 320 includes a request to establish a specific security association between the external agent 58 and the home agent 28, and the H-AAA server 17 requires the specific security association to establish the requested security association. You are required to dynamically assign parameters. These required parameters are the FA-HA shared secret or public / private key pair, authentication algorithm and mode, FA-HA private key lifetime, response protection mechanism (if required), security parameter index (SPI). ) Or security index values, as well as any other required parameters that may be defined in the future.
The H-AAA server 17 may respond with an access denied message if the request is invalid or if any other part of the request is inappropriate. Assuming that the security association request is appropriate, the H-AAA server 17 sends an access request message (RSA) in message 325.<sub>1</sub>) 320 permission message (RSAR)<sub>1</sub>). This permission message (RSAR) in message 325<sub>1</sub>) Contains the requested security association parameters, including the security parameter index value (SPI) with SPI = SPI1. The private key information may be included in message 325.
External agent sends permission message (RSAR) with message 325<sub>1</sub>) Is received, the external agent 58 forwards the initial registration request message (RRQ) to the home agent (HA) with message 330. Message 330 includes an authentication extension with some of the additional security association parameters and security parameter index (SPI) values received from H-AAA server 17 in message 325.
The home agent 28 receives the initial registration request message (RRQ) at message 330, is dynamically assigned by the H-AAA server 17, and the security association value and security association sent to the external agent 58 at message 325. Access request message (RSA) to H-AAA server 17 with a request to disclose the parameter index (SPI) value.<sub>2</sub>) Send 330. Access request message (RSA)<sub>2</sub>) 330 allows the H-AAA server 17 to authenticate and verify the identity of the home agent 28, and the H-AAA server 17 is the home agent from the H-AAA server 17 in message 345. Permission message sent to 28 (RSAR)<sub>2</sub>) Provides the requested security association parameters to the home agent 28. The H-AAA server 17 sends a permission message (RSAR) to the home agent 28 in message 345.<sub>2</sub>) Includes additional security information such as security parameter values and private key information that allows the home agent 28 and external agent 58 to encrypt and decrypt the messaging between their entities.
Home agent 28 has a permission message (RSAR)<sub>2</sub>) Is received, and this permission message allows the home agent 28 to authenticate the registration request (RRQ) originally received from the mobile node 64 via the external agent 58. After this confirmation and authentication, the home agent sends a registration response (RRQ reply) message 350 to the external agent. The external agent authenticates the registration response (RRQ reply) message 350, confirms and authenticates, and then sends the registration response reply message (RRQ reply) 355. Following the reception of message 350, mobile node 64 is registered and there is an established secure communication path between mobile node 64, external agent 58 and home agent 28. The session is registered and the mobile node 64 can communicate with the home agent 28 in a secure manner.
Although the present invention has been specifically shown and described with respect to preferred embodiments, it will be readily appreciated that minor modifications of the invention may be made without departing from the spirit of the invention.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2001169341A | Cites | Japan |
| US20050190734A1 | Cites | United States of America |
| WO2006021236A1 | Cites | World Intellectual Property Organization (WIPO) |
| JP2002534930A | Cites | Japan |
| WO2004112349A1 | Cites | World Intellectual Property Organization (WIPO) |
8 members in 4 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 60908472 | United States of America | – | |
| 90847207 | United States of America | P | |
| 60916866 | United States of America | – | |
| 91686607 | United States of America | P | |
| 2008003992 | United States of America | W |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| WO2008118480A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN101675617A | China | A | |
| US2010106969A1 | United States of America | A1 | |
| JP2010523051A | Japan | A | |
| JP5044690B2This record | Japan | B2 | |
| US8411858B2 | United States of America | B2 | |
| US2013130655A1 | United States of America | A1 | |
| US8615658B2 | United States of America | B2 |
23 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Written notification for declining of transfer of rightsJAPANESE INTERMEDIATE CODE: R360R360 | R360 | |
| Transfer withdrawnWithdrawnJAPANESE INTERMEDIATE CODE: R371R371 | R371 | |
| Written notification for declining of transfer of rightsJAPANESE INTERMEDIATE CODE: R360R360 | R360 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 5044690
- Application
- 2010500993
Titles2
- Japanese
- IPモビリティシステムのための動的な外部エージェント-ホーム・エージェント・セキュリティ・アソシエーション割当て
- English
- Dynamic External Agents for IP Mobility Systems-Home Agent Security Association Assignment
Classification
- CPC, 10
- H04L63/068
- H04L63/08
- H04L63/0892
- H04W8/065
- H04W28/18
- H04W48/14
- H04W60/00
- H04W80/04
- H04W12/04
- H04W12/06
- IPC, 4
- H04W12 06
- H04W80 04
- H04W12 04
- H04W8 04
