Carrier Aggregation Security via KeNB Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for interworking and integration of different radio access networks, such as 3GPP and WLAN, face challenges in efficiently handling authentication and security aspects, leading to duplication of functionalities and potential conflicts, especially in carrier aggregation scenarios.
Innovation Solution
The proposed solution involves configuring a Pairwise Temporal Key (PTK) originating from a key KeNB to enable encryption of data between a wireless device and a base station, using a random number to generate the PTK, and ensuring over-the-air WLAN security for carrier aggregation by forwarding traffic data between the wireless device and the base station via a WLAN access point.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If carrier aggregation is implemented between different radio access networks (3GPP and WLAN), then network integration and data transmission capability are improved, but authentication and security handling complexity increases
Solution Approach 1:
The patent merges the security architectures of 3GPP and WLAN networks by deriving WLAN security keys (PTK, GTK) from the 3GPP KeNB key. This integration eliminates the need for separate authentication procedures in WLAN, as the same key hierarchy is used across both networks, thereby reducing authentication complexity while maintaining network integration capability.
Solution Approach 2:
The KeNB key from 3GPP is made universal for both 3GPP and WLAN security operations. The same key serves multiple functions: it protects 3GPP user plane and control plane data, and also derives the PTK and GTK for WLAN data protection. This multi-functionality reduces the number of separate key management procedures needed.
2Reliability
If separate authentication procedures are used in 3GPP and WLAN networks, then network security is maintained, but functionality duplication and conflicts occur
Solution Approach 1:
The patent combines the authentication procedures of 3GPP and WLAN into a single unified process. The 3GPP AKA authentication establishes the KeNB key, which is then used to derive both 3GPP and WLAN security keys. This eliminates the need for separate WLAN authentication procedures, removing functionality duplication while maintaining security through the unified key hierarchy.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The proposed technology generally relates to interworking and integration of different radio access networks, and more specifically to carrier aggregation between different radio access networks such as a cellular radio access network, e.g. a 3GPP network, on one hand and a WLAN network such as Wi-Fi, on the other hand. Such tight interworking/aggregation of radio access networks puts new requirements on efficient handling of authentication and security aspects. The proposed technology provides methods, and corresponding network nodes, computer programs,carriers comprising such computer programs, and computer program products as well as arrangements to support carrier aggregation between different radio access networks.