Per-Bearer Switching via Security Gateway in LTE-WLAN Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current LTE-WLAN integration solutions face challenges in transparently switching bearer traffic between WWAN and WLAN networks, particularly in legacy WLAN deployments, which can lead to security vulnerabilities and inflexible deployment options, and do not effectively consider load conditions or user mobility.

Innovation Solution

Implementing a security gateway between the WWAN base station and the wireless communication device to establish a secure IPSec tunnel, allowing per-bearer switching of traffic between WWAN and WLAN networks, thereby isolating the WWAN base station from potential attacks and enabling more flexible deployment options.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If direct LTE-WLAN integration is implemented without a security gateway, then deployment flexibility is improved, but security vulnerabilities increase due to base station exposure to malicious attacks

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A security gateway is introduced as an intermediary component between the WLAN and the LTE base station. The gateway establishes IPSec tunnels with the base station and manages WLAN connectivity, thereby protecting the base station from direct exposure to WLAN security threats while maintaining integration functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If per-bearer switching between WWAN and WLAN is implemented, then routing efficiency is improved, but device complexity increases due to the need for security gateway and tunnel management

Engineering Contradiction:
Improverouting efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the bearer traffic into different bearers that can be independently routed. The security gateway maintains separate IPSec tunnel connections for different bearers, allowing selective routing of specific bearers over WLAN while keeping others on WWAN, thereby managing complexity through structured segmentation.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If UE mobility is allowed in LTE-WLAN integration, then adaptability is improved, but IPSec re-establishment frequency increases causing network instability

Engineering Contradiction:
Improveuser mobility supportVSAvoidnetwork stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security gateway implements feedback mechanisms to monitor UE mobility events and IPSec tunnel status. When mobility events occur, the gateway can detect and manage IPSec re-establishment processes, providing feedback control to maintain network stability while allowing necessary mobility.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3360386B1Transparent per-bearer switching between WWAN and WLAN
Publication Date: 2024.03.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3360386B1 patent drawingFigure 1
  • EP3360386B1 patent drawingFigure 2
  • EP3360386B1 patent drawingFigure 3

AI summary

A wireless communication device (12) served by a wireless wide area network (WWAN) base station supports per-bearer switching of bearer traffic between the WWAN and a wireless local area network (WLAN) in a manner transparent to the WLAN. The device in this regard establishes a secure tunnel (24) through the WLAN to a security gateway (22), based on the device receiving a message from the WWAN base station (18) to establish the secure tunnel (24). The device switches bearer traffic between the WWAN and the WLAN on a per bearer basis, with bearer traffic switched to the WLAN being transported through the secure tunnel (24) and over a connection (26) between the security gateway (22) and the WWAN base station (18).