Access Stratum Security Anchor for Wireless Network Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face challenges in securely accessing wireless networks, particularly in managing multiple security contexts and supporting various security features across different services.
Innovation Solution
The proposed solution involves a method and apparatus for securing access to a wireless network by using access stratum (AS) security, where a security service generates and transmits AS keys to wireless nodes, enabling secure connections between devices and wireless nodes based on service security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If core network security functions manage all security contexts, then security management is centralized and controlled, but service flexibility and ability to support varying security requirements across services is reduced
Solution Approach 1:
The patent segments security context management by introducing AS security that operates independently at the access stratum level, separating it from core network security functions. This allows different services to have their own security contexts managed locally at the wireless node, rather than all security being centralized in the core network.
Solution Approach 2:
The patent adds a new dimension to security management by implementing AS security as a separate layer below the traditional NAS security context. This creates a hierarchical security structure where AS security handles access-level security requirements while core network functions handle higher-level security, enabling services to leverage AS security for faster, more flexible security operations.
2Adaptability or versatility
If multiple security contexts are supported for different services, then service-specific security requirements can be met, but security key management becomes more complex
Solution Approach 1:
The patent segments security key management by introducing service-specific AS keys that are generated and managed independently for each service requiring AS security. This segmentation allows each service to have its own security context without requiring the core network to manage all security keys centrally.
Solution Approach 2:
The wireless node performs self-service by generating AS keys locally using the identifier of the wireless device and service-specific parameters. This eliminates the need for the core network to generate and distribute security keys for each service, significantly reducing key management complexity while enabling service-specific security.
3Speed
If AS security is implemented at the access stratum, then security operations can be performed closer to the radio interface improving speed, but new security infrastructure components are required
Solution Approach 1:
The patent implements preliminary action by pre-generating AS keys at the wireless node before services need them. When a service requires security, the AS key is already available locally at the access stratum, enabling immediate security operations without waiting for key distribution from the core network.
Solution Approach 2:
The patent introduces AS security as an intermediary layer between the radio interface and core network security functions. This intermediary handles security operations locally at the access stratum, providing fast security operations while maintaining compatibility with existing core network security infrastructure through the NAS security context.
Data Source
AI summary
An apparatus, method and computer-readable media are disclosed for securing wireless communications. For example, a process for securing access to a wireless network can include: receiving, by a security service from a service, a first request for a service key for accessing the service, the first request for the service key including an identifier for a first wireless node and a service security policy, wherein the service security policy indicates using access stratum (AS) security, and wherein the first wireless node is wirelessly coupled to a wireless device attempting to access the service; transmitting, from the security service in response to the first request for a service key, the service key for accessing the service; generating a first AS key based on the identifier for the first wireless node; and transmitting the generated first AS key to the first wireless node based on the identifier for the first wireless node.


