PDN-GW Security Channel Update via AAA Trust Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of 3GPP mobile communications networks, the PDN-GW struggles to correctly establish or update data security channels when a UE hands over between different access networks (trusted non-3GPP, untrusted non-3GPP, and 3GPP access networks) due to inconsistencies in trust relationships, leading to inadequate security protection for data transmission.
Innovation Solution
An authentication and authorization device sends a message to the PDN-GW with information about the trust relationship of the UE's access, enabling the PDN-GW to establish or update the data security channel accordingly, ensuring correct security associations are maintained across network handovers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If the PDN-GW retains an existing security association SA after handover, then time is saved for SA establishment, but the trust relationship information becomes inconsistent with the current access network, leading to incorrect security channel configuration
Solution Approach 1:
The AAA server provides feedback to the PDN-GW about the current access network type through authorization response messages. This feedback mechanism ensures the PDN-GW has up-to-date trust relationship information to correctly configure security channels, resolving the inconsistency problem when reusing existing SA after handover.
Solution Approach 2:
The system performs preliminary authentication and authorization actions through the AAA server before data transmission begins. The AAA server determines the access network type in advance and communicates this information to the PDN-GW, ensuring the security association is properly configured before actual data flow starts.
2Reliability
If the PDN-GW establishes separate security channels for different access networks, then security protection is improved, but the device complexity and management overhead increase
Solution Approach 1:
The AAA server serves multiple functions: authentication, authorization, and providing access network type information. This multi-functional approach consolidates what would otherwise require separate mechanisms, reducing overall system complexity while maintaining proper security channel management across different access networks.
Solution Approach 2:
The AAA server acts as an intermediary between the access network and the PDN-GW, translating access network type information into appropriate security configuration instructions. This intermediary role simplifies the PDN-GW's task by providing pre-processed authorization information, reducing the complexity of security channel management.
3Adaptability or versatility
If the PDN-GW uses different security mechanisms for trusted and untrusted access networks, then security adaptability is improved, but the difficulty of detecting and measuring the current access scenario increases
Solution Approach 1:
The AAA server autonomously determines the access network type based on information from the access network, without requiring the PDN-GW to implement complex detection mechanisms. The access network itself provides the necessary information to the AAA server, which then handles the classification and communication of access scenario details.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Embodiments of the present invention provide a method and a device for processing a data security channel of a tunnel, where the method includes: receiving an authentication and authorization request of an access side, and determining a trust relationship of access of a user equipment; and when an S6b interface session of the user equipment exists, sending a message including information about the trust relationship of the access of the user equipment to a packet data gateway, so that the packet data gateway establishes or updates a data security channel of an S2c tunnel according to the information about the trust relationship. In the embodiments of the present invention, when a user equipment accesses an EPS network via an S2c interface, and when an authentication and authorization request of an access side is received, if an S6b interface session of the accessed user equipment already exists, a message that includes information about a trust relationship of access of the user equipment is sent to a packet data gateway, so that the packet data gateway can obtain the trust relationship of the user equipment when the user equipment accesses the EPS network via the S2c interface, ensuring correct establishment or update of a data security channel of an S2c tunnel.