IMS Handover via Security Gateway Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in seamlessly handovering Internet Protocol Multimedia Subsystem (IMS) calls from Wi-Fi networks to cellular networks, particularly when the Wi-Fi connection is lost or becomes unreliable, leading to disruptions in service due to differences in network support and security protocols between these networks.

Innovation Solution

A method and apparatus for user equipment (UE) that establishes a secure tunnel over an untrusted Wi-Fi network, using a security gateway, and transitions this tunnel to a cellular network by updating the IP address and security association, enabling continuous IMS service even when the Wi-Fi network is no longer available, through the use of multi-homing protocols like MOBIKE.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure tunnel is established over an untrusted Wi-Fi network for IMS calls, then service availability is improved, but network security risk increases

Engineering Contradiction:
Improveservice availabilityVSAvoidnetwork security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security gateway as an intermediary component between the UE and the untrusted Wi-Fi network. The security gateway establishes the secure tunnel and manages security associations, acting as a mediator that protects the UE from direct exposure to security risks in untrusted networks while enabling IMS service continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If IP address updating is performed during handover from Wi-Fi to cellular network, then service continuity is improved, but handover complexity increases

Engineering Contradiction:
Improveservice continuityVSAvoidhandover complexity
Core Design Contradiction:
Stability of the object's compositionVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by pre-establishing the secure tunnel and security association between the UE and the security gateway before the actual handover occurs. This preliminary setup includes configuring the second source IP address and security parameters in advance, so that when handover is needed, the UE can simply update its IP address and resume service without complex reconfiguration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent utilizes parameter changes by updating the source IP address from the first Wi-Fi assigned address to the second cellular network assigned address. This parameter change enables the UE to maintain its secure tunnel connection while transitioning between networks, allowing service continuity through a straightforward IP address update mechanism.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If multi-homing protocol is used for network transition, then adaptability is improved, but protocol complexity increases

Engineering Contradiction:
Improvenetwork transition capabilityVSAvoidprotocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using the MOBIKE protocol, which provides multi-homing capabilities that work across different network types (Wi-Fi and cellular). The same protocol mechanism enables the UE to transition between different access networks while maintaining secure tunneling, making the solution universally applicable to various network scenarios without requiring network-specific custom protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3672324B1Optimized handovers of wi-fi offload service from a wi-fi network to a cellular network
Publication Date: 2023.12.06 MEDIATEK INC
  • EP3672324B1 patent drawingFigure 1
  • EP3672324B1 patent drawingFigure 2
  • EP3672324B1 patent drawingFigure 3~4B

AI summary

In an aspect of the disclosure, an apparatus is provided. The apparatus connects to a security gateway via a packet data network (PDN) gateway. The apparatus further establishes a secure tunnel between the apparatus and the security gateway using a first source IP address.