Per-Bearer Switching via Security Gateway in LTE-WLAN Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current LTE-WLAN integration solutions face challenges in transparently switching bearer traffic between WWAN and WLAN networks, particularly in legacy WLAN deployments, which can lead to security vulnerabilities and inflexible deployment options, and do not effectively consider load conditions or user mobility.
Innovation Solution
Implementing a security gateway between the WWAN base station and the wireless communication device to establish a secure IPSec tunnel, allowing per-bearer switching of traffic between WWAN and WLAN networks, thereby isolating the WWAN base station from potential attacks and enabling more flexible deployment options.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If direct LTE-WLAN integration is implemented without a security gateway, then deployment flexibility is improved, but security vulnerabilities increase due to base station exposure to malicious attacks
Solution Approach 1:
A security gateway is introduced as an intermediary component between the WLAN and the LTE base station. The gateway establishes IPSec tunnels with the base station and manages WLAN connectivity, thereby protecting the base station from direct exposure to WLAN security threats while maintaining integration functionality.
2Productivity
If per-bearer switching between WWAN and WLAN is implemented, then routing efficiency is improved, but device complexity increases due to the need for security gateway and tunnel management
Solution Approach 1:
The system segments the bearer traffic into different bearers that can be independently routed. The security gateway maintains separate IPSec tunnel connections for different bearers, allowing selective routing of specific bearers over WLAN while keeping others on WWAN, thereby managing complexity through structured segmentation.
3Adaptability or versatility
If UE mobility is allowed in LTE-WLAN integration, then adaptability is improved, but IPSec re-establishment frequency increases causing network instability
Solution Approach 1:
The security gateway implements feedback mechanisms to monitor UE mobility events and IPSec tunnel status. When mobility events occur, the gateway can detect and manage IPSec re-establishment processes, providing feedback control to maintain network stability while allowing necessary mobility.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A wireless communication device (12) served by a wireless wide area network (WWAN) base station supports per-bearer switching of bearer traffic between the WWAN and a wireless local area network (WLAN) in a manner transparent to the WLAN. The device in this regard establishes a secure tunnel (24) through the WLAN to a security gateway (22), based on the device receiving a message from the WWAN base station (18) to establish the secure tunnel (24). The device switches bearer traffic between the WWAN and the WLAN on a per bearer basis, with bearer traffic switched to the WLAN being transported through the secure tunnel (24) and over a connection (26) between the security gateway (22) and the WWAN base station (18).