User's Manual
CHAPTER 4. Message Flow
4-6
© SAMSUNG Electronics Co., Ltd.
At the Time of Authenticator Relocation
When the MS performs the CSN-anchored Handover (HO), or the Idle Mode MS moves to
another ACR area and performs the location update, the following re-authentication
procedure is performed to move the authenticator from the existing Serving ACR to the
Target ACR. The Target ACR triggers in order that the MS performs the EAP authentication
procedure with the AAA server again, and then, when the result of the authentication result
is notified to the Serving ACR, the Authenticator Relocation procedure is completed.
Figure 4.3 Authentication Procedure (At the time of the Authenticator Relocation)
Classification Description
(1)~(2) The new authenticator, T-ACR, exchanges the Relocation Notify/Ack message with
the previous authenticator, S-ACR, to perform re-authentication and authenticator
relocation.
(3)~(11) The new authenticator, T-ACR, exchanges the Relocation Notify/Ack message with
the previous authenticator, S-ACR, to perform re-authentication and authenticator
relocation.
(12)~(13) The RAS sends the Key Change Confirm message to the authenticator (T-ACR) to
notify it that re-authentication is complete with the MS.
(14)~(16) The T-ACR completes the authenticator relocation procedure by exchanging the
Relocation Confirm/Ack message with the S-ACR.
(17)~(18) After the authenticator relocation, the new authenticator notifies the anchor that the
authenticator has been changed through the context Rpt procedure.
MS T-RAS
AAA
T-ACR S-ACR
6) DEA
4) PKMv2-RSP
8) PKMv2-RSP
3) AuthRelay EAP Transfer
11) SA-TEK handshake
7) AuthRelay EAP Transfer
9) Key Change Directive
10) Key Change Directive Ack
12) Key Change Confirm
13) Key Change Confirm Ack
5) Serving ASN triggers MS re-authentication with AAA Server
14) Relocation Complete_Req
15) Relocation Complete_Rsp
1) Relocation Notify
2) Relocation Notify Ack
17) Context_Rpt
18) Context_Ack
16) Relocation_Complete_Ack