LTE-WLAN Aggregation Security Key Update Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP systems face challenges in managing security key updates for WLAN termination (WT) during handovers in LTE-WLAN aggregation, leading to Quality of Experience (QoE) degradation due to frequent key changes, and lack clarity on when and how to refresh keys independently in LTE and WLAN networks.

Innovation Solution

A method is introduced to detect security key update triggering events in the base station, performing a WT modification procedure and subsequent release and addition procedures to update security keys, allowing for controlled key changes based on specific events, thereby addressing the need for efficient and secure key management across different network scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security key is updated frequently during handovers in LTE-WLAN aggregation, then security is improved, but Quality of Experience (QoE) degrades due to frequent key changes affecting high data rate transmissions

Engineering Contradiction:
ImprovesecurityVSAvoidQoE
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by making the key update mechanism adaptive rather than static. The base station dynamically decides whether to trigger a WT modification procedure based on the handover type (intra-eNB vs. inter-eNB) and network conditions, allowing the system to optimize between security and QoE in real-time

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of key update frequency and timing based on different handover scenarios. Instead of uniform frequent updates, the system adjusts update behavior according to whether the handover is intra-eNB (less frequent updates acceptable) or inter-eNB (more frequent updates needed), thereby optimizing the security-QoE trade-off

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security key update procedures are implemented for every handover event, then security is maintained, but system complexity increases due to multiple procedures (WT modification, release, addition)

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management process into distinct procedures: WT modification procedure for key updates, WT release procedure for tearing down connections, and WT addition procedure for establishing new connections. This segmentation allows each procedure to be handled independently and optimally based on the specific handover scenario

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by preparing the WT modification procedure to be triggered selectively before actual key updates are needed. The base station evaluates handover types in advance and pre-determines whether to initiate key update procedures, avoiding unnecessary complexity in routine intra-eNB handovers while maintaining security in critical inter-eNB scenarios

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3466135B1Method and system for authenticating access in mobile wireless network system
Publication Date: 2022.01.05 SAMSUNG ELECTRONICS CO LTD
  • EP3466135B1 patent drawingFigure 1~2
  • EP3466135B1 patent drawingFigure 3
  • EP3466135B1 patent drawingFigure 4

AI summary

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Embodiments herein achieve a method for authenticating access in a mobile wireless network system. The method includes receiving by an Extensible Authentication Protocol (EAP) authenticator an EAP packet encapsulated from an access terminal over a high rate packet data radio link and a signaling interface through a radio access network. The EAP packet is encapsulated over at least one of a Non-Access Stratum (NAS) interface, a Radio Resource Control (RRC) interface and a N1 interface. The EAP authenticator is located at a secured node in a core network of the radio access network. Further, the method includes authenticating by the EAP authenticator at least one of a network access subscription and a service of the access terminal.