Fast Transition Key Reuse Between Private WWA and WLA Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems experience significant delays in transitioning between wireless wide area (WWA) and local area (WLA) access networks, particularly in mobile communication environments, due to the need for multiple authentication and key derivation steps, which can take up to 8-10 seconds.
Innovation Solution
Leveraging 3GPP-generated session keys from a secondary or primary authentication process to generate IEEE 802.11r Fast Transition (FT) key material, allowing for rapid authentication and connection establishment between WWA and WLA networks by reusing master keys obtained during prior authentication exchanges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication and key derivation steps are performed during transition between WWA and WLA networks, then security and authentication reliability are improved, but transition time and connection establishment delay increase
Solution Approach 1:
The patent performs authentication and key derivation actions in advance during the WWA network connection establishment. The master key and security context are established beforehand in the WWA network, so when transitioning to WLA network, these pre-established credentials can be reused immediately without repeating the full authentication process, thus reducing transition time while maintaining security
Solution Approach 2:
The patent merges the authentication processes of WWA and WLA networks by establishing a unified security context that spans both networks. The master key derived in WWA authentication is reused for WLA network authentication, combining what would otherwise be separate authentication sequences into a single unified process, thereby eliminating redundant steps and reducing overall transition time
2Reliability
If multiple authentication and key derivation steps are performed during transition between WWA and WLA networks, then security and authentication reliability are improved, but productivity and connection establishment speed decrease
Solution Approach 1:
The authentication credentials and master key are established in advance during WWA network connection. This preliminary action ensures that when the device needs to connect to WLA network, the security context is already prepared, eliminating the need to perform time-consuming authentication steps again, thus improving connection establishment speed while maintaining security reliability
Solution Approach 2:
The patent creates a copy of the master key and security context from the WWA network authentication process and uses this copied credential for WLA network authentication. Instead of regenerating security credentials, the system copies and reuses the existing master key, significantly accelerating the connection establishment process while maintaining the same security level
3Reliability
If traditional authentication processes are used for WLA network connection, then security protocols are followed, but user experience for latency-sensitive applications deteriorates due to service interruptions
Solution Approach 1:
Security credentials and master keys are established in advance during WWA network connection before the user needs to access WLA services. This preliminary security setup ensures that when latency-sensitive applications require WLA network access, the authentication is already complete, eliminating service interruptions and providing seamless user experience while maintaining full security protocol compliance
Solution Approach 2:
The patent introduces a mobility management entity that acts as an intermediary between WWA and WLA networks. This intermediary maintains the security context and master key information, enabling smooth transitions between networks without requiring users to experience authentication delays or service interruptions, thus improving ease of operation while preserving security
Data Source
AI summary
Presented herein are techniques to provide for the ability to utilize 3GPP-generated Session Keys that can be generated via a primary authentication or a secondary authentication process for a user equipment (UE) via a private wireless wide area (WWA) access network in which the keys can be leveraged to facilitate connection of the UE to a wireless local area (WLA) access network. In one example, a method may include obtaining a request to authenticate a UE for connection to a WWA access network; determining that the UE is capable of a Fast Transition (FT) capability; authenticating the UE for connection to the WWA access in which, based on the FT capability, the authenticating includes generating a root security key for the UE; and upon determining that the UE is attempting to access the WLA access network, providing the root security key for the UE to the WLA access network.


