Cloud Cell Security Key Management for Wireless Handovers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In high-frequency band wireless communication systems, the frequent handovers of mobile stations (MS) between base stations (BS) increase system overhead and require efficient authentication procedures for data exchange, especially with the increased number of BSs per unit area.

Innovation Solution

A method and apparatus for managing security keys in a cloud cell-based communication system, where a master BS and slave BSs work together to provide authentication and encryption keys for secure data transmission, using a cloud seed or identifier-based key generation to facilitate seamless handovers and reliable communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Area of stationary object

If the cell radius of the BS is reduced to support high-capacity data services in high-frequency band, then the service coverage can be secured, but the number of inter-cell handovers of the MS increases

Engineering Contradiction:
Improvecell radiusVSAvoidhandover frequency
Core Design Contradiction:
Area of stationary objectVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating and distributing authentication contexts from the master BS to all slave BSs before handover occurs. When an MS hands over to a slave BS, authentication can proceed immediately using the pre-delivered context, eliminating the need for time-consuming authentication procedures during handover.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication function by introducing a master BS that centrally manages authentication contexts and distributes them to multiple slave BSs. This segmentation allows slave BSs to independently authenticate MSs using pre-delivered contexts without needing to communicate with the master BS during handover, reducing handover latency.

Inventive Principle:
Principle #1Segmentation

2Area of stationary object

If the number of BSs per unit area is increased to secure service area, then the service coverage is improved, but the system overhead increases due to frequent handovers

Engineering Contradiction:
Improveservice coverageVSAvoidsystem overhead
Core Design Contradiction:
Area of stationary objectVSDevice complexity

Solution Approach 1:

Authentication contexts are pre-generated and distributed to slave BSs before handover events occur. This preliminary distribution of authentication information eliminates the need for repeated authentication procedures during frequent handovers, significantly reducing system overhead in dense BS deployments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The master BS creates copies of authentication contexts and distributes them to multiple slave BSs. Each slave BS receives an identical copy of the authentication context, enabling independent authentication without requiring real-time communication with the master BS, thus reducing signaling overhead.

Inventive Principle:
Principle #26Copying

3Reliability

If authentication procedure is performed whenever serving BS is changed, then communication security is maintained, but the authentication time and system overhead increase

Engineering Contradiction:
Improvecommunication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The master BS performs authentication context generation and distribution to slave BSs in advance, before any handover occurs. This preliminary action ensures that authentication information is readily available at slave BSs, enabling immediate authentication without time delays during handover events while maintaining security through centralized context management.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The master BS acts as an intermediary that centrally manages authentication contexts and distributes them to slave BSs. This intermediary role ensures that security is maintained through centralized control while enabling fast authentication at slave BSs using pre-delivered contexts, resolving the contradiction between security and speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9380459B2Method and apparatus for managing security keys for communication authentication with mobile station in wireless communication system
Publication Date: 2016.06.28 SAMSUNG ELECTRONICS CO LTD
  • US9380459B2 patent drawing
  • US9380459B2 patent drawing
  • US9380459B2 patent drawing

AI summary

Provided is a method for managing a security key for communication authentication with a Mobile Station (MS) in a communication system. The method includes acquiring a first authentication key by performing an authentication procedure for the communication authentication in a cloud cell having member Base Stations (BSs) that include a master BS and at least one slave BS for providing a service to the MS; and communicating with at least one member BS using a first encryption key that is generated using the first authentication key.