Cloud Cell Security Key Management for Wireless Handovers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In high-frequency band wireless communication systems, the frequent handovers of mobile stations (MS) between base stations (BS) increase system overhead and require efficient authentication procedures for data exchange, especially with the increased number of BSs per unit area.
Innovation Solution
A method and apparatus for managing security keys in a cloud cell-based communication system, where a master BS and slave BSs work together to provide authentication and encryption keys for secure data transmission, using a cloud seed or identifier-based key generation to facilitate seamless handovers and reliable communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Area of stationary object
If the cell radius of the BS is reduced to support high-capacity data services in high-frequency band, then the service coverage can be secured, but the number of inter-cell handovers of the MS increases
Solution Approach 1:
The patent applies preliminary action by pre-generating and distributing authentication contexts from the master BS to all slave BSs before handover occurs. When an MS hands over to a slave BS, authentication can proceed immediately using the pre-delivered context, eliminating the need for time-consuming authentication procedures during handover.
Solution Approach 2:
The patent segments the authentication function by introducing a master BS that centrally manages authentication contexts and distributes them to multiple slave BSs. This segmentation allows slave BSs to independently authenticate MSs using pre-delivered contexts without needing to communicate with the master BS during handover, reducing handover latency.
2Area of stationary object
If the number of BSs per unit area is increased to secure service area, then the service coverage is improved, but the system overhead increases due to frequent handovers
Solution Approach 1:
Authentication contexts are pre-generated and distributed to slave BSs before handover events occur. This preliminary distribution of authentication information eliminates the need for repeated authentication procedures during frequent handovers, significantly reducing system overhead in dense BS deployments.
Solution Approach 2:
The master BS creates copies of authentication contexts and distributes them to multiple slave BSs. Each slave BS receives an identical copy of the authentication context, enabling independent authentication without requiring real-time communication with the master BS, thus reducing signaling overhead.
3Reliability
If authentication procedure is performed whenever serving BS is changed, then communication security is maintained, but the authentication time and system overhead increase
Solution Approach 1:
The master BS performs authentication context generation and distribution to slave BSs in advance, before any handover occurs. This preliminary action ensures that authentication information is readily available at slave BSs, enabling immediate authentication without time delays during handover events while maintaining security through centralized context management.
Solution Approach 2:
The master BS acts as an intermediary that centrally manages authentication contexts and distributes them to slave BSs. This intermediary role ensures that security is maintained through centralized control while enabling fast authentication at slave BSs using pre-delivered contexts, resolving the contradiction between security and speed.
Data Source
AI summary
Provided is a method for managing a security key for communication authentication with a Mobile Station (MS) in a communication system. The method includes acquiring a first authentication key by performing an authentication procedure for the communication authentication in a cloud cell having member Base Stations (BSs) that include a master BS and at least one slave BS for providing a service to the MS; and communicating with at least one member BS using a first encryption key that is generated using the first authentication key.


