LTE-WLAN Aggregation Security Key Update Mechanism
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP systems face challenges in managing security key updates for WLAN termination (WT) during handovers in LTE-WLAN aggregation, leading to Quality of Experience (QoE) degradation due to frequent key changes, and lack clarity on when and how to refresh keys independently in LTE and WLAN networks.
Innovation Solution
A method is introduced to detect security key update triggering events in the base station, performing a WT modification procedure and subsequent release and addition procedures to update security keys, allowing for controlled key changes based on specific events, thereby addressing the need for efficient and secure key management across different network scenarios.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security key is updated frequently during handovers in LTE-WLAN aggregation, then security is improved, but Quality of Experience (QoE) degrades due to frequent key changes affecting high data rate transmissions
Solution Approach 1:
The patent applies dynamics by making the key update mechanism adaptive rather than static. The base station dynamically decides whether to trigger a WT modification procedure based on the handover type (intra-eNB vs. inter-eNB) and network conditions, allowing the system to optimize between security and QoE in real-time
Solution Approach 2:
The patent changes the parameter of key update frequency and timing based on different handover scenarios. Instead of uniform frequent updates, the system adjusts update behavior according to whether the handover is intra-eNB (less frequent updates acceptable) or inter-eNB (more frequent updates needed), thereby optimizing the security-QoE trade-off
2Reliability
If security key update procedures are implemented for every handover event, then security is maintained, but system complexity increases due to multiple procedures (WT modification, release, addition)
Solution Approach 1:
The patent segments the key management process into distinct procedures: WT modification procedure for key updates, WT release procedure for tearing down connections, and WT addition procedure for establishing new connections. This segmentation allows each procedure to be handled independently and optimally based on the specific handover scenario
Solution Approach 2:
The patent applies preliminary action by preparing the WT modification procedure to be triggered selectively before actual key updates are needed. The base station evaluates handover types in advance and pre-determines whether to initiate key update procedures, avoiding unnecessary complexity in routine intra-eNB handovers while maintaining security in critical inter-eNB scenarios
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Embodiments herein achieve a method for authenticating access in a mobile wireless network system. The method includes receiving by an Extensible Authentication Protocol (EAP) authenticator an EAP packet encapsulated from an access terminal over a high rate packet data radio link and a signaling interface through a radio access network. The EAP packet is encapsulated over at least one of a Non-Access Stratum (NAS) interface, a Radio Resource Control (RRC) interface and a N1 interface. The EAP authenticator is located at a secured node in a core network of the radio access network. Further, the method includes authenticating by the EAP authenticator at least one of a network access subscription and a service of the access terminal.