Base Station Security Parameter Handling for UE-AP Offloading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing network congestion due to high user demand and data services in communications networks poses challenges in ensuring communication quality, and existing data offloading methods, such as WiFi, suffer from low security in data transmission between user equipment (UE) and WiFi access points (APs).

Innovation Solution

A communication security processing method where a base station determines the need for UE to access an AP, acquires and sends a security parameter to ensure secure data exchange, enhancing security by activating a secure air interface for data transmission between UE and AP.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data offloading to WiFi is implemented to relieve network congestion, then network capacity and throughput are improved, but data transmission security between UE and AP deteriorates

Engineering Contradiction:
Improvenetwork throughputVSAvoiddata transmission security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The base station acts as an intermediary between the UE and AP, acquiring security parameters from the AP and securely transmitting them to the UE through the secure air interface. This intermediary role enables the base station to bridge the security gap in WiFi offloading without compromising network throughput.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The base station acquires security parameters from the AP before the UE establishes direct communication with the AP. By performing this security setup in advance through the secure air interface, the system ensures security is in place before data transmission begins, resolving the security concern while maintaining throughput benefits.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security parameters are transmitted over the air interface, then data transmission security is improved, but network complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The base station automatically performs security parameter acquisition and transmission without requiring manual configuration or complex security management procedures. The system self-manages the security setup process, reducing operational complexity while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The base station performs multiple functions including normal data transmission, security parameter acquisition, and secure parameter distribution through the same air interface. This multi-functionality avoids adding separate complex security infrastructure, simplifying the overall system while improving security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10172003B2Communication security processing method, and apparatus
Publication Date: 2019.01.01 HUAWEI TECH CO LTD
  • US10172003B2 patent drawing
  • US10172003B2 patent drawing
  • US10172003B2 patent drawing

AI summary

The present invention provides a communication security processing method and an apparatus. The communication security processing method includes: determining, by a base station, that user equipment UE needs to access an access point AP; acquiring, by the base station, a security parameter that is required for the UE to interact with the AP; after an air interface is securely activated, sending, by the base station, the security parameter to the UE, so that the UE performs, by using the security parameter, security processing on data exchanged between the UE and the AP. According to the communication security processing method and the apparatus that are provided in the present invention, a security air interface between UE and a base station is used to transfer a security-related parameter, which improves data communication security, and enhances network control performed by an operator.