IP Library Patent Application 11183526
Patent Application
App. No. 11/183,526

Scheme for resolving authentication in a wireless packet data network after a key update

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/183,526
Abstract

In one embodiment, a scheme is disclosed for resolving authentication of a mobile node that negotiates with a packet data serving node (PDSN) for establishing a Simple IP (SIP) connection after encountering a failure in Mobile IP (MIP) service mode.

Claims (39)

1 . A method for resolving authentication of a mobile node disposed in a wireless packet data network, comprising:

upon being rendered in a Simple Internet Protocol (SIP) service mode, attempting by said mobile node to negotiate a SIP connection with a packet data serving node (PDSN) of said wireless packet data network;

responsive to a first authentication protocol proposed by said PDSN, counter-proposing by said mobile node of a second authentication protocol for use; and

upon acknowledging said second authentication protocol by said PDSN, effectuating an authentication procedure in accordance with said second authentication protocol, wherein said authentication procedure uses a set of authentication keys, a first one provided with said mobile node and a second one provided with said PDSN, that have been updated in a key update process.

2 . The method for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 1 , wherein said first authentication protocol comprises Password Authentication Protocol (PAP) and said second authentication protocol comprises Challenge Handshake Authentication Protocol (CHAP).

3 . The method for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 1 , wherein said mobile node is configured to be activated in a Mobile IP (MIP) service mode upon initialization.

4 . The method for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 3 , wherein said mobile node effectuates said key update process during initial MIP registration.

5 . The method for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 3 , wherein said key update process comprises a Dynamic MIP Update (DMU) process.

6 . The method for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 3 , wherein said mobile node is placed in said SIP service mode upon encountering a failure in said MIP service mode.

7 . The method for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 6 , wherein said failure in said MIP service mode results from an outage of a Home Agent associated with said mobile node.

8 . The method for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 1 , wherein said first authentication protocol is proposed by said PDSN via a first Link Control Protocol (LCP) message to said mobile node.

9 . The method for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 8 , wherein said second authentication protocol is counter-proposed by said mobile node via a second LCP message to said PDSN.

10 . A system for resolving authentication of a mobile node disposed in a wireless packet data network, comprising:

means associated with said mobile node for negotiating a Simple Internet Protocol (SIP) connection with a packet data serving node (PDSN) of said wireless packet data network, said means operating responsive to said mobile node being rendered in a SIP service mode;

means associated with said mobile node for counter-proposing a second authentication protocol for use after rejecting a first authentication protocol proposed by said PDSN; and

means, operable upon acknowledging said second authentication protocol by said PDSN, for effectuating an authentication procedure in accordance with said second authentication protocol, wherein said authentication procedure uses a set of authentication keys, a first one provided with said mobile node and a second one provided with said PDSN, that have been updated in a key update process.

11 . The system for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 10 , wherein said first authentication protocol comprises Password Authentication Protocol (PAP) and said second authentication protocol comprises Challenge Handshake Authentication Protocol (CHAP).

12 . The system for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 10 , wherein said mobile node is configured to be activated in a Mobile IP (MIP) service mode upon initialization.

13 . The system for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 12 , further comprising means associated with said mobile node for effectuating said key update process during initial MIP registration.

14 . The system for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 12 , wherein said mobile node is placed in said SIP service mode upon encountering a failure in said MIP service mode.

15 . The system for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 14 , wherein said failure in said MIP service mode results from an outage of a Home Agent associated with said mobile node.

16 . The system for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 10 , wherein said first authentication protocol is proposed by said PDSN via a first Link Control Protocol (LCP) message to said mobile node.

17 . The system for resolving authentication of a mobile node disposed in a wireless packet data network as recited in claim 16 , wherein said second authentication protocol is counter-proposed by said mobile node via a second LCP message to said PDSN.

18 . A mobile node operable in a wireless packet data network, comprising:

logic for negotiating a Simple Internet Protocol (SIP) connection with a packet data serving node (PDSN) of said wireless packet data network, said logic operating responsive to said mobile node being rendered in a SIP service mode;

logic for counter-proposing a second authentication protocol for use after rejecting a first authentication protocol proposed by said PDSN; and

logic for effectuating an authentication procedure in accordance with said second authentication protocol once said second authentication protocol is acknowledged by said PDSN, wherein said authentication procedure uses a set of authentication keys, a first one provided with said mobile node and a second one provided with said PDSN, that have been updated in a key update process.

19 . The mobile node operable in a wireless packet data network as recited in claim 18 , wherein said first authentication protocol comprises Password Authentication Protocol (PAP) and said second authentication protocol comprises Challenge Handshake Authentication Protocol (CHAP).

20 . The mobile node operable in a wireless packet data network as recited in claim 18 , further comprising logic for activating said mobile node in a Mobile IP (MIP) service mode upon initialization.

21 . The mobile node operable in a wireless packet data network as recited in claim 20 , further comprising logic for effectuating said key update process during initial MIP registration.

22 . The mobile node operable in a wireless packet data network as recited in claim 20; further comprising logic for placing said mobile node in said SIP service mode upon encountering a failure in said MIP service mode.

23 . The mobile node operable in a wireless packet data network as recited in claim 18 , wherein said logic for effectuating an authentication procedure in accordance with said second authentication protocol includes logic for generating a response to a challenge issued by said PDSN.

24 . The mobile node operable in a wireless packet data network as recited in claim 23 , wherein said response is generated based upon said first key that has been updated in said key update process.

25 . A packet data serving node (PDSN) operable in a wireless packet data network, comprising:

logic for determining that a mobile node has updated a set of authentication keys provided in accordance with a particular authentication protocol for authenticating said mobile node, said set of authentication keys including a first one provided with said mobile node and a second one provided with said PDSN; and

logic for effectuating an authentication procedure in accordance with said particular authentication protocol when said mobile node attempts to negotiate a Simple Internet Protocol (SIP) connection with said PDSN upon being rendered in a SIP service mode, wherein said authentication procedure uses said set of authentication keys that have been updated in a key update process.

26 . The PDSN operable in a wireless packet data network as recited in claim 25 , wherein said particular authentication protocol comprises Challenge Handshake Authentication Protocol (CHAP).

27 . The PDSN operable in a wireless packet data network as recited in claim 25 , wherein said logic for effectuating an authentication procedure in accordance with said particular authentication protocol includes logic for generating a challenge to said mobile node.

28 . The PDSN operable in a wireless packet data network as recited in claim 27 , wherein said logic for effectuating an authentication procedure in accordance with said particular authentication protocol further includes logic for validating a response transmitted by said mobile node, said validating being based on said second key associated with said PDSN that has been updated in said key update process.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Oct 20, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 034016/0738 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2005
From: ISLAM, MUHAMMAD KHALEDUL; KIM, JIN; CHAUDRY, SHAHID RASUL
To: RESEARCH IN MOTION LIMITED
Reel/Frame 016787/0483 →