Access Stratum Security Anchor for Wireless Network Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face challenges in securely accessing wireless networks, particularly in managing multiple security contexts and supporting various security features across different services.

Innovation Solution

The proposed solution involves a method and apparatus for securing access to a wireless network by using access stratum (AS) security, where a security service generates and transmits AS keys to wireless nodes, enabling secure connections between devices and wireless nodes based on service security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If core network security functions manage all security contexts, then security management is centralized and controlled, but service flexibility and ability to support varying security requirements across services is reduced

Engineering Contradiction:
Improveservice security flexibilityVSAvoidsecurity context management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security context management by introducing AS security that operates independently at the access stratum level, separating it from core network security functions. This allows different services to have their own security contexts managed locally at the wireless node, rather than all security being centralized in the core network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to security management by implementing AS security as a separate layer below the traditional NAS security context. This creates a hierarchical security structure where AS security handles access-level security requirements while core network functions handle higher-level security, enabling services to leverage AS security for faster, more flexible security operations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If multiple security contexts are supported for different services, then service-specific security requirements can be met, but security key management becomes more complex

Engineering Contradiction:
Improveservice-specific security supportVSAvoidsecurity key management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security key management by introducing service-specific AS keys that are generated and managed independently for each service requiring AS security. This segmentation allows each service to have its own security context without requiring the core network to manage all security keys centrally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The wireless node performs self-service by generating AS keys locally using the identifier of the wireless device and service-specific parameters. This eliminates the need for the core network to generate and distribute security keys for each service, significantly reducing key management complexity while enabling service-specific security.

Inventive Principle:
Principle #25Self-service

3Speed

If AS security is implemented at the access stratum, then security operations can be performed closer to the radio interface improving speed, but new security infrastructure components are required

Engineering Contradiction:
Improvesecurity operation speedVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-generating AS keys at the wireless node before services need them. When a service requires security, the AS key is already available locally at the access stratum, enabling immediate security operations without waiting for key distribution from the core network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces AS security as an intermediary layer between the radio interface and core network security functions. This intermediary handles security operations locally at the access stratum, providing fast security operations while maintaining compatibility with existing core network security infrastructure through the NAS security context.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250056221A1Access stratum security anchor for a wireless network service security architecture
Publication Date: 2025.02.13 QUALCOMM INC
  • US20250056221A1 patent drawing
  • US20250056221A1 patent drawing
  • US20250056221A1 patent drawing

AI summary

An apparatus, method and computer-readable media are disclosed for securing wireless communications. For example, a process for securing access to a wireless network can include: receiving, by a security service from a service, a first request for a service key for accessing the service, the first request for the service key including an identifier for a first wireless node and a service security policy, wherein the service security policy indicates using access stratum (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; transmitting, from the security service in response to the first request for a service key, the service key for accessing the service; generating a first AS key based on the identifier for the first wireless node; and transmitting the generated first AS key to the first wireless node based on the identifier for the first wireless node.