Access Point Key Generation for Seamless Wireless Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in seamless mobility between trusted non-3GPP access points, requiring re-authentication and disrupting connectivity when a user equipment moves between access points connected to the same gateway function, leading to service interruptions.

Innovation Solution

The system determines a change of connection from a source access point to a target access point, generates an access point key based on the indication that the associated gateway function is the same for both, and secures communications using this key, allowing for authorized key generation without full authentication, thus enabling smooth mobility without service disruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If re-authentication is performed when user equipment moves between access points, then security is maintained, but service continuity is interrupted and authentication latency increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing security context and generating access point keys in advance during initial authentication. When mobility occurs between access points, the pre-established security context is reused through the gateway function, eliminating the need for time-consuming re-authentication while maintaining security requirements

Inventive Principle:
Principle #10Preliminary action

2Reliability

If re-authentication is performed when user equipment moves between access points, then security is maintained, but service continuity is interrupted

Engineering Contradiction:
ImprovesecurityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The gateway function serves multiple purposes: it acts as a security anchor point for authentication, a key management entity for generating access point keys, and a mobility management node for maintaining service continuity. This multi-functionality allows the system to maintain security while enabling seamless handover between access points without service interruption

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If full authentication protocols are used during mobility, then security is ensured, but resource consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of performing complete authentication protocols during mobility events, the system applies partial action by reusing the previously established security context and gateway function identification. This partial approach maintains necessary security verification while significantly reducing the computational and energy resources consumed by the user equipment during handover operations

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240155439A1Securing communications at a change of connection
Publication Date: 2024.05.09 NOKIA TECHNOLOGIES OY
  • US20240155439A1 patent drawing
  • US20240155439A1 patent drawing
  • US20240155439A1 patent drawing

AI summary

There is provided an apparatus comprising means for determining a change of connection at a user equipment from a source access point to a target access point, and means for receiving, from the target access point, an indication that an associated gateway function is the same for the source access point and the target access point. The apparatus also comprising means for generating an access point key based on the received indication from the target access point, and means for securing communications with the target access point using the generated access point key.