Common Key Generation for 5G Multi-RAT Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G mobile communication systems face challenges in providing efficient multi-RAT security architecture, leading to redundancy in authentication and security setup processes when a user equipment (UE) accesses different radio access technologies (RATs) within the same core network, resulting in increased delay and overhead.
Innovation Solution
A method and apparatus that enable a UE to access multiple networks within the same core network without re-authentication by performing an initial authentication procedure with a node having an authentication server function, generating a common key, and using this key to generate security keys for each network, thereby reducing the need for separate re-authentication during handovers or LWA operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication and security setup are performed for each RAT access, then security requirements for each network are met, but authentication delay and signaling overhead increase
Solution Approach 1:
The patent performs authentication and security setup in advance during initial network attachment, storing security context information including keys and identifiers. When the UE later accesses a different RAT within the same core network, the pre-stored security context is reused, eliminating the need for re-authentication and reducing delay while maintaining security requirements
Solution Approach 2:
The patent creates a universal security context that can be reused across multiple RATs (3GPP and non-3GPP accesses) within the same core network. The security setup performed once serves multiple access technologies, reducing redundant authentication procedures while meeting security requirements for each RAT
2Reliability
If separate authentication and security setup are performed for each RAT access, then network security is ensured, but signaling overhead increases
Solution Approach 1:
The patent merges the security setup process across different RATs by creating a unified security context that encompasses multiple access technologies. Instead of performing separate authentication procedures for each RAT, the security context is established once and reused across 3GPP and non-3GPP accesses, significantly reducing signaling overhead while maintaining network security
Solution Approach 2:
The patent performs security setup in advance during initial network attachment, storing security context information including keys and identifiers. This preliminary security establishment eliminates the need for repeated signaling exchanges during subsequent RAT accesses, reducing overall signaling overhead while ensuring continuous network security
3Productivity
If a common security key is generated for multiple networks, then authentication efficiency improves, but security architecture complexity increases
Solution Approach 1:
The patent segments the security architecture into distinct components: a common security context containing reusable elements (keys, identifiers) and access-specific parameters. This segmentation allows efficient reuse of common security elements across multiple RATs while maintaining separate control over RAT-specific security parameters, managing complexity through structured organization
Solution Approach 2:
The patent creates a universal security context that serves multiple RATs simultaneously. The common security key and associated context can be reused across 3GPP and non-3GPP accesses, improving authentication efficiency. The complexity is managed by establishing clear rules for key derivation and context reuse that apply uniformly across different access types
Data Source
AI summary
A method for performing a security procedure by a terminal in a wireless communication system, and an apparatus thereof. The method includes transmitting a first access request message for accessing a first network of a core network to a first radio access network (RAN) node, performing an authentication procedure for mutual authentication with a node performing an authentication server function (AUSF) of the core network, generating a common key commonly used in one or more networks included in the core network based on an authentication vector obtained through the mutual authentication procedure, generating a first base key of the first network based on the common key and a network code corresponding to a type of the first network, and receiving an access accept message indicating an access accept of the first network from the first RAN node.


