Method for establishing security association and method for secure fast handover in Proxy Mobile IP

31-07-2015 дата публикации
Номер:
KR0101540523B1
Контакты:
Номер заявки: 01-13-102057853
Дата заявки: 18-12-2013

[1]

The present invention refers to proxy mobile IP protocol (Proxy Mobile IP protocol; PMIP) relates to, IPv6 a mobile node in S102 (Mobile Node; MN), mobile access gateway (MAG; Mobile Access Gateway) and local mobility anchor (Local Mobility Anchor) (security association) security association between for etching and secure method for setting and quickly handover capable of treating relates to method.

[2]

Mobile IPv6 (MIPv6) the mobile node (Mobile Node; MN) one access router (access router) to another access router IP to the handover to a supporting a mobility (IP mobility). For this purpose, in of the mobile node MIPv6 IPv6. switchover from the client stack. Furthermore, mobile node and home agent (Home Agent; HA) through exchange of messages the signalling requirements between the home address of the mobile node (Home Address; HoA) and an auxiliary address (Care-of address; CoA) (binding) of creation and maintenance of binding between..

[3]

IP other method for supporting mobility IPv6 proxy mobile as (Proxy MIPv6; PMIPv6) is present. PMIPv6 the mobile node and home agent the signalling requirements between host and generate a message it is highlighted supporting the mobility of a nodes IPv6 is characterised in that it has a. I.e., ontrol data mobility agent on behalf of the mobile node is (proxy mobility agent) mobility management signaling is performed in network. PMIPv6 (functional entities) entities core functions defined in a local mobility anchor (Local Mobility Anchor; LMA) and an access gateway is (Mobile Access Gateway; MAG). First, of a home agent of the LMA MIPv6 serves mainly as an address of the mobile node for managing the binding state (binding state). Next, the access link MAG mobility of nodes mobile connected to associated with signaling and manages. I.e., the access node MAG to or access node and sensing movement of mobile node, LMA of the mobile node may perform registration with the binding and to fix an arm serves performs.

[4]

However, packet loss or (latency) handover delay even PMIPv6 in terms (packet loss) basic performance difference't MIPv6 and a separate fasteners or. The select filter, for a handover a fast PMIPv6 PMIPv6 (Fast Handover for PMIPv6)-FH has been proposed. The mobile node is PMIPv6-FH subnet new packet upon sensing link to transmit the RF and, new MAG connection using is sensed immediately transmits it mobile node packets.

[5]

While, PMIPv6 an appropriate signaling messages where there is no protection scheme, the change of the flow as in MIPv6 PMIPv6 (redirection), denial of service (Denial of Service; DoS), (replay) and reproducing MITM (Main In The Middle) device includes an organic membrane comprising such attack effected using the security attacks exploit't capable. Recent, PMIPv6 signaling messages for protecting authentication system (authentication scheme) to a higher melting of color cathode proceeds, of vulnerability to attacks exploit part still is situation.

[6]

The discharge of the torch electrode from said for the purpose of the invention, in proxy mobile IPv6, security attacks exploit various can cope, mobile node (MN) and an access gateway (MAG) liver and mobile access gateway (MAG) and local mobility anchor (LMA) efficiently security association between for establishing a by a rope. provides method.

[7]

The discharge of the torch electrode from said for it is another object of the present invention, proxy mobile IPv6 in, various digital network user part in exchane security attacks exploit while also being capable of capable of fast operation, provides for processing handover method by a rope..

[8]

The present invention refers to the callee opens the folder of his said, ontrol data in mobile IPv6 (PMIPv6), mobile node and mobile access gateway (MAGA) is and said mobile access gateway (MAGA) and local mobility anchor (LMA) method for setting the security association between in, said mobile node from said mobile access gateway (Authentication, Authorization and Accounting) said mobile node and AAA symmetric key sharing server (symmetric key) KMN masterbatches prepared from session key (K*) of message authentication code (MAC) (RtrSol) message including the steps of receiving, said master session key said mobile access gateway (K*) of message authentication code (MAC) (Auth_Req) authorization request message including a AAA server transmitting the and said mobile access gateway in response to the authorization request message said mobile node and said mobile access gateway (MAGA) is shared among a the session key (KMN- 888000000888 8) and said mobile access gateway (MAGA) and said local mobility anchor (LMA) is shared among a the session key (KLMA-MAGA) authentication responses is included (Auth_Rsp) message including a command is sent from said AAA server, proxy mobile IPv6 provides security connection setup method.

[9]

Here, the method said security association setting said mobile access gateway mobile access gateway (MAGA) and said local mobility anchor (LMA) is shared among a the session key (KLMA-MAGA) (PBU) binding update ontrol data including said message (LMA) transmitting the local mobility anchor may include further.

[10]

Here, the setting security association said method said mobile node and said mobile access gateway mobile access gateway (MAGA) is shared among a the session key (KMN-MAGA) is said (RtrAdv) a message comprising a further step of transmitting to a mobile node may include.

[11]

Here, said authentication request (Auth_Req) message the mobile access gateway its secret key said (SKMAGA) performs a signature using may include (signature).

[12]

Here, the message (Auth_Rsp) said said AAA server its secret key authentication response (SKAAA) performs a signature using may include (signature).

[13]

Here, said authorization request message transmission and said authentication response message reception initial domain PMIPv6 said mobile node is including access can be.

[14]

Here, said master session key (K*) said PMIPv6 in the domain the mobile node is performing a session and at the end to effective outside the can be constructed.

[15]

Here, said session key (KMN-MAGA) the master session key (K*) and said mobile access gateway (MAGA) the pseudo-random based identifier of the can be produced by the function.

[16]

Here, said session key (KLMA-MAGA) the master session key (K*), said mobile access gateway (MAGA) said local mobility anchor (LMA) and an identifier of the pseudo-random based identifier of the can be produced by the function.

[17]

said present invention refers to for achieving other purposes, in proxy mobile IPv6 (PMIPv6), number 1 of the mobile node mobile access gateway (MAGA) number 2 from mobile access gateway (MAGB) a method for processing handover to in, said number 2 mobile node is said number 1 mobile access gateway mobile access gateway said handing over recognizing that step, said number 1 mobile access gateway local mobility anchor (LMA) said number 2 to mobile access gateway (MAGB) of an authentication request identifier are provided with the e-message (Auth_Req) said number 1 and prints the mobile access gateway said mobile node and said local mobility anchor from said number 2 mobile access gateway (MAGB) is shared among a the session key (KMN-MAGB) and a, mobile access gating said local mobility anchor said number 2 (MAG won (MAGB) is shared among a the session key (KLMA-MAGB) authentication responses is included (Auth_Rsp), the method including receiving a message, proxy mobile IPv6 provides method for processing hand-over in.

[18]

Here, said local mobility anchor (LMA) mobile access gateway and the number 1 and manages both gateway mobile access said number 2.

[19]

Here, said mobile node from said recognizing step mobile access gateway identifier of said number 2 (MAGB) message including (Start_Auth) to receiving an. may be brought about by.

[20]

Here, the method for processing handover said said number 1 said number 2 anchor mobility local said mobile access gateway mobile access gateway (MAGB) is shared among a the session key (KLMA-MAGB) message including said number 2 a step of transmitting to a mobile access gateway may include further.

[21]

Here, said session key (KMN-MAGB) and said session key (KLMA-MAGB) AAA mobile node and the (Authentication, Authorization and Accounting) symmetric key sharing server (symmetric key) KMN masterbatches prepared from session key (K*) can be produced based on.

[22]

The, said master session key (K*) said mobile node is the local mobility anchor (LMA) is a mobile terminal only when wave remains in the domain PMIPv6 can be effective.

[23]

The, said session key (KMN-MAGB) said number 2 the master session key (K*) and a mobile access gateway (MAGB) the pseudo-random based identifier of the can be produced by the function.

[24]

The, said session key (KLMA-MAGB) the master session key (K*) and said local mobility anchor and number 2 mobile access gateway (MAGB) the pseudo-random based identifier of the can be produced by the function.

[25]

The, said session key (KMN-MAGB) and said session key (KLMA-MAGB) the, AAA (Authentication, Authorization and Accounting) the reaction and does not server, said local key distribution's a lower cavity and a local mobility anchor (LMA) can be produced in.

[26]

In the present invention, security mechanisms based on AAA for PMIPv6 is incurring. The present invention according to PMIPv6 a secure connection setup the surface of the substrate method, mobile node and mobile access gateway between security association and a mobile access gateway and a local mobility anchor between. can be established security association. Furthermore, a new secret keys by the protective signaling messages can be, existing PMIPv6 PMIPv6-FH and can be if security.

[27]

Furthermore, in the present invention conventional PMIPv6-FH in a half-handover of to minimize local mobility anchor local key distribution center (local key distribution center) consists of to to take on the role of an. The, key authentication server AAA in during handover from a procedure is required, handover delay is prevented, handover delay according to packet loss are. can be prevented in addition.

[28]

Figure 1 shows a general outline IPv6 (PMIPv6) proxy mobile also to explain the operation of is general outline. Also Figure 2 shows a fast handover proxy mobile IPv6 general outline (PMIPv6-FH) to explain the operation of is general outline. Also the present invention according to embodiment a network architectures, and Figure 3 shows a key hierarchy applied substracte the present invention according to (key hierarchy) is describing general outline. Also the present invention according to Figure 4 shows a proxy mobile IPv6 (PMIPv6) a secure connection setup is general outline to explain the method. Also the present invention according to Figure 5 shows a proxy mobile IPv6 (PMIPv6) handover processing method is to explain the general outline.

[29]

Various modification of the present invention refers to various embodiment thereby, the cold air flows that can apply which may have bar, specific drawing illustrated in the embodiment are defined in the description are disclosed and. rapidly and to reduce a memory. However, the present invention with a particular embodiment of the physical shape not defined to be, included within the scope of the present invention all changing a concept and techniques, including replacement water and equalization should understood. Each drawing while describes similar references in a similar was to use components.

[30]

Number 1, number 2, A, a set of terms, such as B describes various elements which may be used; however, said components are said terms is don't is defined by. Said terms are components of one an object from other components is carried out by using an acidulous only. For example, rights of the present invention without a wireless type through a wire number 1 number 2 component can be designated components, similarly number 2 number 1 component elements can be designated. And/or a substrate having a number of associated term of items combination or plurality of associated a substrate of items includes which item.

[31]

To other components is any component "is connected" know "is connected" when-mentioned that, that different structural elements thereof connected directly to or may be is connected, intermediate the other components may be present that. to be understood. While, to other components is any component "is directly connected with the" know "are directly connected" when-mentioned that, intermediate the other components there is no will should be understood.

[32]

The present application only a term use in a particular embodiment used to describe the thereby, the cold air flows are added, is not intending to be defining the present invention. Contextually representation a plurality of differently it is apparent that without the carelessly, includes multiple representations. In the present application, "comprising" or "having ." a set of terms, such as a specification to the features, number, step, operation, components, component or a combination of these is designates the feature to which is present does, number to execute another aspect of one or more, step, operation, components, component or a combination of these existence of a without excluding the possibility or additionally pre should understood.

[33]

Other is not defined, technical or scientific for a term including to the all terms are person with skill in the art in the present invention is in the field of the upwardly urged by equivalent to those that would have been understood have the meanings of wet liquid to flow down. Generally are defined as the dictionary used for, such as terms are on wherein the nodes refining the context of related techniques consistent semantics and having having the meanings must be interpreted to, the present application, become manifest in a do not define, excessively or is ideal for the widest sense of the formal does not interpreted.

[34]

Hereinafter, the present invention according to a preferred embodiment by issuing an thereby, the cold air flows rapidly and to reduce a memory reference to drawing..

[35]

Figure 1 shows a general outline IPv6 (PMIPv6) proxy mobile also to explain the operation of is general outline.

[36]

Also 1 with a, mobile node (101) is PMIPv6 domain (105) in entering of in, mobile node (101) a mobile access gateway (102) (access link) access link of access link that each including mobile access gateway (102) is PMIPv6. cause the computer system to perform operation.

[37]

First, mobile node (101) after the connected to the access link RtrSol (Router Solicitation) message ((1)) to a mobile access gateway (102) and transmits the to. The, with specific transmission time point of a message RtrSol free are restrictions, mobile node (101) is later connected to access link can be is what point the.

[38]

Next, mobile access gateway (102) the of the mobile node to local mobility anchor (LMA; 103) notifies the current position of the mobile node the ontrol data for binding update (PBU; Proxy Binding Update) message ((2)) a packet suitable for an ieee802.. PBU local mobility the anchor receives a message confirming binding ontrol data response (PBA; Proxy Binding Acknowledge) message is for transmitting ((3)). The, prefix home network of the mobile node the message PAB (HNP; Home Network Prefix) .may be included. The, local mobility anchor binding cache in an entry for the mobile node (Binding Cache Entry; BCE) generates a mobile access gateway (102), bidirectional tunneling for its set a (end-point) end point side. The BCE (identifier) identifier of the mobile node, home network prefix, time stamp values and mobile nodes associated with. may be incorporated other information. On the other hand, receives a message PBA mobile access gateway (102) the, local mobility anchor (103), bidirectional tunneling for its is set between an end point side. I.e., the mobile node, bidirectional tunneling produced (101) of traffic local mobility anchor (103) forwarding it to be used for.

[39]

Next, mobile access gateway (102) the RtrAdv (Router Advertisement) message ((4)) to the mobile node (101), and transmits the. The, prefix home network of the mobile node the message RtrAdv (HNP) may be included which is, at a mobile node which receives it and its interface HNP can be set based on.

[40]

After, local mobility anchor (103) the PMIPv6 domain (105) present and out any node for the mobile node from receiving packets that are being transmitted the hierarchically anchor points and downwardly on a curved portion (anchor point) light incident from the light, received packets are setting two-way tunnel access gateway (102) are transferred in, again mobile access gateway (102) from mobile node through the access link (101) is transferred to a.

[41]

Also Figure 2 shows a fast handover proxy mobile IPv6 general outline (PMIPv6-FH) to explain the operation of is general outline.

[42]

Also refers to surface 2, mobile node (201) is number 1 mobile access gateway (202) number 2 from mobile access gateway (204) a handover alarm is exemplary.

[43]

In PMIPv6-FH, mobile node when it detects that to have undergone an impending handover is informed number 2 receives a random number mobile access gateway (204) number 1 to discern an identifier of a mobile access gateway (are currently connected mobile access gateway) is the relays installed to (not shown).

[44]

After, mobile access gateway number 1 (202) number 2 and a mobile access gateway (204) the HI (Handover Initiate) message ((2)) ((1)) and a Hack (Handover acknowledgement) message by device and exchanging said, sets the, bidirectional tunneling between each other. Setting two-way via a tunnel mobile node (201) number 1 the packets toward mobile access gateway (202) number 2 in mobile access gateway (204) is transferred to a (handover temporarily until the completion of).

[45]

Local mobility anchor (203) and a mobile access gateway number 2 (204) has a sequence such as described ((3)) and a PBA message PBU message exchange is ((4)). PBU message and PBA message exchange through the local mobility anchor (203) in binding cache is updated when, mobile node (201) packets into or mobile node (201) number 1 the packets from mobile access gateway (202) the reaction and does not, number 2 mobile access gateway (204) directly is serpentine.

[46]

Finally number 2 mobile access gateway (204) the mobile node (201) to RtrAdv (Router Advertisement) message may send a ((5)). The, prefix home network of the mobile node the message RtrAdv (HNP) may be included which is, at a mobile node which receives it and its interface HNP can be set based on.

[47]

In hereinafter, the present invention according to PMIPv6 a secure connection setup method and handover processing method to explain the several terms defining the before.

[48]

MN, MAGA, MAGB, LMA each mobile node, number 1 mobile access gateway (MAGA), number 2 mobile access gateway (MAGB) and local mobility anchor (LMA) (abbreviation) abbreviation of the/ear however, the context (in particular, in Figure 5 and 4 also) corresponding component identifier (identifier) provided that the mixture by the addition of an initiator.

[49]

PKX and a SKX disclosure of each X (public key) key (secret key; private key) secret key and a. mixture by the addition of an initiator. SA (X, Y) between the X and a Y. (Security Association) security association. All fields preceding has MAC (K) K for message authentication code is computed using the. mixture by the addition of an initiator (Message Authentication Code). PKX the disclosure key PKX a message using a means (encryption) encryption m, Sig[SKX] preceding has secret key for all fields SKX using an apparatus of a digital signature (digital signature)..

[50]

Furthermore, in hereinafter, T0 means time stamp is initially, T1 for the time stamp of the handover point..

[51]

Figure 3 shows a a network architectures, and also applied substracte the present invention according to the present invention according to embodiment (key hierarchy) is key hierarchy that describes a general outline.

[52]

Also 3 with a, mobile node relate the present invention according to embodiment (301) is number 1 mobile access gateway (302) are connected in on a concentric circle from a, number 2 again mobile access gateway (304) to being handed over is. taking into account the network.

[53]

The, mobile node (301) the AAA server (305) various provided with a wire of the present invention and a method through an setting long term symmetric key (long-term symmetric key; KMN; 311) sharing a is located in. I.e., AAA server (305) and a mobile node (301) module is installed under the security association is predetermined is home is that it. This also be refers to 4 and in Figure 5. similar to that of the.

[54]

Long-term symmetric key (KMN) from session key (K*; master session key; 312) is generated. Furthermore, local mobility anchor (303) number 1 the mobile access gateway (302) and number 2 mobile access gateway (304) is connected, and manages both. Number 1 mobile access gateway (302) and a mobile access gateway number 2 (304) the same PMIPv6 domain (306) is included.

[55]

While, also 3 again a, mobile node (301) and a AAA server (305) for all of the secret keys (key hierarchy) layer the key may allow a user to access. While, mobile access gateways the mobile node or local mobility anchor share the first. access only secret key.

[56]

In the present invention, mobile node and mobile access gateway whose lists are session key (313), mobile access gateway and a local mobility anchor whose lists are session key (314) the aforementioned master session keys generated from. Master session key PMIPv6 domain session said terminal when expiration since key effective outside the, mobile node and mobile access gateway whose lists are session key and mobile access gateway and a local mobility anchor whose lists are compared to session key a master session key shorter. for an effective period of time. [...] only, these features is setting security association the present invention according to a high method for processing handover or method having security can be which causes the slower to.

[57]

In the present invention, each freshness of a signaling message to ensure one time stamp values is used in. The mobile node, mobile access gateway mobility and a local timestamp time the anchor remains of the cache. Signaling message is received, time stamp values checks the new message when the system is moved to the message authentication code (MAC; Message Authentication Code) of is carried out. For example, time stamp (T1) when message is received is recorded, received time stamp (T1) and a current time stamp recorded in a cache time stamp (T0) compares a a. T1 > T0 the currently received only when judges whether a new message, to a message received protocol processing is performed on. If, T1 > T0 were not for, messages received at the all protocol interrupts the operation of an a coverage.

[58]

In hereinafter, the present constitution of the invention the main component which has an two is described in the context of. PMIPv6 initial authentication procedure first (initial authentication procedure) security in a second method which connection setup, a second method for processing hand-over in PMIPv6 relates to, authentication process in processing handover in particular the following formula 1. (handover authentication procedure).

[59]

Also the present invention according to Figure 4 shows a connection setup a secure IPv6 (PMIPv6) mobile ontrol data to explain the method is general outline

[60]

Also refers to surface 4, mobile node (401) the first domain PMIPv6 (406) when the. are exampled, of procedures.

[61]

First, mobile node (401) is initially time stamp (T0) and a master session key (K*) generates a. The, master session key (K*) mobile node with the AAA server (401) between groups corresponding to already shared key (KMN) and said initial time stamp (T0) can be produced based on. E.g., shared key (KMN) and a time stamp (T0) a as inputs, the output of pseudo random function (pseudo random function) said master session key (K*) .can be determined. I.e., K* =prf (KMN, T0) can be represented by.

[62]

Next, mobile node (401) a master session key the generated (K*) using message including message authentication code (MAC) (e.g., RtrSol (Router Solicitation) message ((1))) to a mobile access gateway (402), and transmits the. MAC refers to acknowledgements are to be authentication response (Auth_Rsp) message to the mobile access gateway is is made after receiving the.

[63]

Mobile access gateway (402) the mobile node (401) (RtrSol message) message is transmitted after receiving an, received its own secret key (SKMAGA) performs a signature using (Sig (SKMAGA)) authorization request message a purifier of cars (Auth_Req message ((2))) for AAA server (405), and transmits the. AAA server included in a message containing a checks that the digital signature with MAC, a message when the discards the. interrupting the progression of procedure. AAA server (405) the contained in a message confirmation result of the digital signature with MAC, problem session key if the key is inputted, (KMN-MAGA) and a session key (KLMA-MAGA) generates a, generated session key (KMN-MAGA) and a session key (KLMA-MAGA) for authenticating response message (Auth_Rsp message ((3))) in mobile access gateway (402), and transmits the.

[64]

The, session key (KMN-MAGA) the mobile node (401) and an access gateway (402) which a session whose lists are, said master session key (K*) and a mobile access gateway identifier of said (MAGA) the pseudo-random based on can be produced by the function. In addition. Session key (KLMA-MAGA) the local mobility anchor (403) and a mobile access gateway (402) which a session whose lists are, said master session key (K*), said mobile access gateway (MAGA) said local mobility anchor (LMA) and an identifier of the pseudo-random based identifier of the can be produced by the function. As the aforementioned, said mobile node is master session key (K*) is a session performed in the domain said PMIPv6 and at the end so that effective outside the, said session key (KMN-MAGA) and a session key (KLMA-MAGA) are said PMIPv6 in addition said mobile node is a session performed in the domain outside the effective effective and at the end.

[65]

These session keys (Auth_Rsp message) said authentication response message in access gateway mobile in disclosure key (PKMAGA) included encrypted by. Authentication response message (Auth_Rsp) the local mobility of the anchor a surrounding key disclosure (PKLMA) by an encrypted master session key (K*) and a of the mobile node identifier (MN) in addition may be included. Furthermore, authentication response message (Auth_Rsp) the AAA server (405) its secret key (SKAAA) performs a signature using (Sig (SKAAA)) is additional.

[66]

Mobile access gateway (402) authentication response message upon receiving a (Auth_Rsp), authentication responses received session key is included in a message to (KMN-MAGA) and a session key (KLMA-MAGA) using future mobile node (401) and local mobility anchor (403) is to encrypt messages signaling with.

[67]

Next, mobile access gateway (402) the session key (KLMA-MAGA) a is computed using the MAC for PBU message ((4)) of the lower side from the anchor through the local mobility, local mobility anchor from through PBA message ((5)) may receive a response. Next, mobile access gateway (402) the session key (KMN-MAGA) for MAC using the calculated perspectives and a mobile node through RtrAdv message ((6)) (401) be capable to deliver the reactant to.

[68]

Here, PBU message, PBA message, also prior the initiator, a role that each message RtrAdv 1 and 2 through the. same as.

[69]

Also the present invention according to Figure 5 shows a proxy mobile IPv6 (PMIPv6) handover processing method is to explain the general outline.

[70]

Also refers to surface 5, mobile node (501) mobile access gateway the number 1 (502) of number 2 in access link mobile access gateway (504) of. is being handed over, and connected in access link.

[71]

First, mobile node (501) has made its own number 1 mobile access gateway (502) from mobile access gateway number 2 (504) is handover procedure to surface noticing that impending, the informed number 2 mobile access gateway (504) identifier of (MAGB) and a time stamp (T1) Start_Auth message including number 1 ((1)) are currently connected a mobile access gateway (502), and transmits the.

[72]

Therefore, mobile access gateway number 1 (501) the mobile node (501) is number 1 mobile access gateway (502) from mobile access gateway number 2 (504) to handover soon will be. it detects that.

[73]

The, number 1 mobile access gateway (501) mobile access gateway identifier of the number 2 (MAGB) and a time stamp (T1) includes an authentication request (Auth_Req) message ((2)) a local mobility anchor (503) of the lower side from the, local mobility anchor (503) from mobile node (501) and a mobile access gateway number 2 (504) is shared among a the session key (KMN-MAGB) and local mobility anchor (503) number 2 and a mobile access gateway (504) is shared among a the session key (KLMA-MAGB) includes authentication responses (Auth_Rsp) message ((3)): this recorder receives. Said session key (KMN-MAGB) and a session key (KLMA-MAGB) the number 2 mobile access gateway (504) its secret key (PKMAGB) the authentication response is encrypted with (Auth_Rsp) may be included, authentication request (Auth_Req) message for the mobile number 2 key in access gateway (PKMAGB) can be included in.

[74]

The, said local mobility anchor (LMA) mobile access gateway and said number 2 the number 1 mobile access gateway both can be component of which managing, mobile access gateway mobile access gateway and number 1 number 2 the same PMIPV6. to the terminal, referring to a in the domain.

[75]

On the other hand, said session key (KMN-MAGB) and a session key (KLMA-MAGB) through 4 also a sequence has the inventive security association setting method much like an session keys in, said mobile node and AAA server (been omitted the in Figure 5) is shared by a symmetric key (symmetric key) KMN masterbatches prepared from session key (K*) can be produced based on. Here, master session key (K*) the mobile node (501) is number 1 mobile access gateway (502) to changed the initial access is enabled already generated (also through the inventive initial authentication procedure 4).

[76]

The aforementioned as, master session key (K*) said PMIPv6 in the domain the mobile node is performing a session and at the end so that effective outside the, said session key (KMN-MAGB) and a session key (KLMA-MAGB) in addition master session key is valid only in a period of time can be effective. Said session key (KMN-MAGB) the master session key (K*) and a mobile access gateway identifier of said number 2 (MAGB) based on the pseudo-random by the function can be generated, said session key (KLMA-MAGB) the master session key (K*) and said local mobility anchor and mobile access gateway identifier of number 2 (LMA, MAGB) the pseudo-random based on patterns can be produced by the function..

[77]

Next, mobile access gateway number 1 (501) ((4)) the HI message number 2 through the mobile access gateway authentication response message prior to the received session key (KMN-MAGB) and a session key (KLMA-MAGB) for delivery of, Hack message number 2 mobile access gateway from: this recorder receives the responses with ((5)). The, session key (KMN-MAGB) and a session key (KLMA-MAGB) mobile access gateway its secret key the number 2 (PKMAGB) is encrypted with the HI message may be included in ((4)).

[78]

Next, mobile access gateway number 2 (504) the PBU message ((7)) ((6)) and a PBA message through the local mobility anchor (503) and a session key (KLMA-MAGB) performs verification on can be.

[79]

Next, mobile access gateway number 2 (504) the RtrAdv message ((8)) through the mobile node (501) to session key (KMN-MAGB) using the calculated perspectives and a can communicate to a MAC.

[80]

Here, PBU message, PBA message, also prior the initiator, a role that each message RtrAdv 1 and 2 through the. same as.

[81]

At least one fatty acid, as longitude, the present invention according to security association setting method and, for processing handover method then, the result of calculation pick current density is.

[82]

First, in the present invention according to security association setting method mobile access gateway and a local mobility anchor as well as security association between, mobile access mobile node and is connection is set up between the security between the. Therefore, these application signaling messages are shared keys by. or the.

[83]

Secondly, in method for processing handover the present invention according to key authentication server AAA process initial access procedure (also 4 through security is described where connection setup method) by which is only performed turn 1, handover system controls an local mobility anchor local key distribution center (local key distribution center) parking equipment is provided to to take on the role of an, AAA server key authentication procedure is performed is allows avoiding the need. Therefore, handover of low efficiency in the course without delay. performance of a rapid handover from one.

[84]

Third, the present invention according to the method for processing handover and method setting security association a mobile node is session key is carried out in corresponding PMIPv6 domain the session and at the end outside the effective. Furthermore, whenever handover is generated is publication newly session key. The, session key from inadvertent exposure of the existing method method, even when the publication a plurality of valves is security of the components on the two. relatively low.

[85]

[86]

Thereby, the cold air flows to standardize the reference to a preferred embodiment of the present invention not described but, corresponding art patent the following is claimed is a classic mirror server one skilled in the art of the present invention is a concept and region within such a range that causes no away from the present invention various modified and change can be 2000 database for each consumer.

[87]

301: mobile node 302: number 1 mobile access gateway 303: local mobility anchor 304: number 2 mobile access gateway 305: AAA server 306 : PMIPv6 domain 311: mobile node and shared key server AAA 312: master session key 313, 314: session key



[88]

PMIPv6 a secure connection setup is disclosure is method for processing handover and method. The method for setting the security association, mobile access gateway mobile node of message authentication code (MAC) master session key receives the message and including, message authentication code (MAC) master session key of an authorization request message including the AAA server, in response to the authorization request message mobile access mobile node and key and the session is shared among a gateway mobile access gateway and a local mobility anchor is shared among a the session key authentication responses message receiving from AAA server may include a process. Therefore, a new secret keys by the protective signaling messages can be, existing PMIPv6 PMIPv6-FH and can be if security.



Ontrol data in mobile IPv6 (PMIPv6), mobile node and mobile access gateway (MAGA) is and said mobile access gateway (MAGA) and local mobility anchor (LMA) method for setting the security association between in, said mobile node from said mobile access gateway (Authentication, Authorization and Accounting) said mobile node and AAA symmetric key sharing server (symmetric key) KMN masterbatches prepared from session key (K*) of message authentication code (MAC) (RtrSol) message including the steps of receiving; said master session key said mobile access gateway (K*) of message authentication code (MAC) (Auth_Req) authorization request message including a transmitting the server AAA; and said said mobile access gateway in response to the authorization request message said mobile node and said mobile access gateway (MAGA) be shared between number 1 session key (KMN-MAGA) and said mobile access gateway 8 880001254888A) and said local mobility anchor (LMA) number 2 session key be shared between (KLMA-MAGA) authentication responses is included (Auth_Rsp) message including a command is sent from said AAA server, proxy mobile IPv6 of security association setting method.

According to Claim 1, said said mobile access gateway mobile access gateway (MAGA) and said local mobility anchor (LMA) number 2 session key be shared between (KLMA-MAGA) (PBU) message binding update ontrol data including said local mobility anchor (LMA) transmitting the received from said authentication response message (Auth_Rsp) for said AAA server including further and then, proxy mobile IPv6 of security association setting method.

According to Claim 1, said said mobile node and said mobile access gateway mobile access gateway (MAGA) be shared between number 1 session key (KMN-MAGA) is a message comprising a (RtrAdv) said step of transmitting to a mobile node (Auth_Rsp) said authentication response message received from said AAA server including further and then, proxy mobile IPv6 of security association setting method.

According to Claim 1, said number 1 session key (KMN-MAGA) the master session key (K*) and said mobile access gateway (MAGA) based identifier of the produced by the pseudo-random function, proxy mobile IPv6 of security association setting method.

According to Claim 1, said number 2 session key (KLMA-MAGA) the master session key (K*), said mobile access gateway (MAGA) and an identifier of said local mobility anchor (LMA) based identifier of the produced by the pseudo-random function, proxy mobile IPv6 of security association setting method.

Ontrol data in mobile IPv6 (PMIPv6), number 1 of the mobile node mobile access gateway (MAGA) number 2 from mobile access gateway (MAGB) a method for processing handover to in, said number 2 said mobile node is said number 1 mobile access gateway mobile access gateway step recognizing that handing over; said number 1 mobile access gateway local mobility anchor (LMA) said number 2 to mobile access gateway (MAGB) of an authentication request identifier are provided with the e-transmitting a message (Auth_Req); and said local mobility anchor from said number 1 mobile access gateway said number 2 mobile node and said mobile access gateway (MAGB) be shared between number 1 session key (KMN-MAGB) and a, said local mobility anchor mobile access gateway (MAG 8880000 246888) be shared between said number 2 number 2 session key (KLMA-MAGB) (Auth_Rsp) authentication responses is included, the method including receiving a message, proxy mobile IPv6 method for processing hand-over in.

According to Claim 6, said local mobility anchor said number 1 said number 2 mobile access gateway mobile access gateway (MAGB) be shared between number 2 session key (KLMA-MAGB) message including said number 2 a step of transmitting to a mobile access gateway said authentication response (Auth_Rsp) then ' receiving a message intended further including, proxy mobile IPv6 method for processing hand-over in.

According to Claim 6, said number 1 session key (KMN-MAGB) and said number 2 session key (KLMA-MAGB) AAA mobile node and the (Authentication, Authorization and Accounting) symmetric key sharing server (symmetric key) KMN masterbatches prepared from session key determined by the (K*), proxy mobile IPv6 method for processing hand-over in.

According to Claim 6, said number 1 session key (KMN-MAGB) and said number 2 session key (KLMA-MAGB) the, AAA (Authentication, Authorization and Accounting) the reaction and does not server, said local key distribution's a lower cavity and a local mobility anchor created at a (LMA), proxy mobile IPv6 method for processing hand-over in.