Mobile Station Security Context Management for Base Station Handovers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile broadband systems with multiple base stations serving a single mobile station, existing security methods require frequent key updates due to changes in the base station configuration, leading to inefficiencies in packet processing and increased complexity for the mobile station.
Innovation Solution
A method where the mobile station and data gateway maintain a security context, with the mobile station and base stations performing security processing for data and control packets respectively, using established security keys that remain valid even when the mobile station moves between base stations, eliminating the need for frequent key updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If frequent key updates are performed due to base station configuration changes, then security is maintained, but processing efficiency deteriorates and complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing security contexts between the mobile station and data gateway before handovers occur. The security keys are generated and stored in advance, allowing the mobile station to maintain secure communication without performing frequent key updates during base station changes, thus improving processing efficiency while maintaining security
2Reliability
If frequent key updates are performed due to base station configuration changes, then security is maintained, but device complexity increases
Solution Approach 1:
The patent reduces mobile station complexity by performing preliminary actions to establish and store security contexts before handovers. The mobile station maintains pre-generated security keys and security contexts, eliminating the need for complex real-time key update operations during base station configuration changes
3Reliability
If security processing is performed at base stations for each mobile station, then security is maintained, but processing overhead increases during handovers
Solution Approach 1:
The patent applies preliminary action by establishing security contexts between the mobile station and data gateway before handovers occur. This pre-establishment eliminates the need for time-consuming security re-processing during handovers, reducing handover processing time while maintaining security through the pre-configured security contexts
Data Source
AI summary
The present invention provides a method and an apparatus for securing data packets and control messages in a mobile broadband network environment. In one embodiment, a mobile station and a data gateway are peers for securing data packets. That is, security context for data packets is maintained at the mobile station and the data gateway. Further, security processing for data packets is performed by the mobile station and the data gateway. In another embodiment, the mobile station and a base station are peers for securing control messages. That is, security context for control messages is maintained at the mobile station and the base station(s). Further, security processing for control messages is performed by the mobile station and the base station(s).


