PDN-GW Security Channel Update via AAA Trust Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of 3GPP mobile communications networks, the PDN-GW struggles to correctly establish or update data security channels when a UE hands over between different access networks (trusted non-3GPP, untrusted non-3GPP, and 3GPP access networks) due to inconsistencies in trust relationships, leading to inadequate security protection for data transmission.

Innovation Solution

An authentication and authorization device sends a message to the PDN-GW with information about the trust relationship of the UE's access, enabling the PDN-GW to establish or update the data security channel accordingly, ensuring correct security associations are maintained across network handovers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If the PDN-GW retains an existing security association SA after handover, then time is saved for SA establishment, but the trust relationship information becomes inconsistent with the current access network, leading to incorrect security channel configuration

Engineering Contradiction:
ImproveSA establishment timeVSAvoidsecurity channel correctness
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The AAA server provides feedback to the PDN-GW about the current access network type through authorization response messages. This feedback mechanism ensures the PDN-GW has up-to-date trust relationship information to correctly configure security channels, resolving the inconsistency problem when reusing existing SA after handover.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary authentication and authorization actions through the AAA server before data transmission begins. The AAA server determines the access network type in advance and communicates this information to the PDN-GW, ensuring the security association is properly configured before actual data flow starts.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the PDN-GW establishes separate security channels for different access networks, then security protection is improved, but the device complexity and management overhead increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity channel management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The AAA server serves multiple functions: authentication, authorization, and providing access network type information. This multi-functional approach consolidates what would otherwise require separate mechanisms, reducing overall system complexity while maintaining proper security channel management across different access networks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The AAA server acts as an intermediary between the access network and the PDN-GW, translating access network type information into appropriate security configuration instructions. This intermediary role simplifies the PDN-GW's task by providing pre-processed authorization information, reducing the complexity of security channel management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the PDN-GW uses different security mechanisms for trusted and untrusted access networks, then security adaptability is improved, but the difficulty of detecting and measuring the current access scenario increases

Engineering Contradiction:
Improvesecurity mechanism adaptabilityVSAvoidaccess scenario determination
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The AAA server autonomously determines the access network type based on information from the access network, without requiring the PDN-GW to implement complex detection mechanisms. The access network itself provides the necessary information to the AAA server, which then handles the classification and communication of access scenario details.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2763357B1Data security channel processing method and device
Publication Date: 2019.03.13 HUAWEI TECH CO LTD
  • EP2763357B1 patent drawingFigure 1~2
  • EP2763357B1 patent drawingFigure 3~4
  • EP2763357B1 patent drawingFigure 5~6

AI summary

Embodiments of the present invention provide a method and a device for processing a data security channel of a tunnel, where the method includes: receiving an authentication and authorization request of an access side, and determining a trust relationship of access of a user equipment; and when an S6b interface session of the user equipment exists, sending a message including information about the trust relationship of the access of the user equipment to a packet data gateway, so that the packet data gateway establishes or updates a data security channel of an S2c tunnel according to the information about the trust relationship. In the embodiments of the present invention, when a user equipment accesses an EPS network via an S2c interface, and when an authentication and authorization request of an access side is received, if an S6b interface session of the accessed user equipment already exists, a message that includes information about a trust relationship of access of the user equipment is sent to a packet data gateway, so that the packet data gateway can obtain the trust relationship of the user equipment when the user equipment accesses the EPS network via the S2c interface, ensuring correct establishment or update of a data security channel of an S2c tunnel.