Pre-registration Security Context Management for Multi-Access Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods fail to effectively maintain multiple security contexts for communication devices operating on multiple access technologies, leading to issues during handovers between different radio access networks.

Innovation Solution

A method that generates and manages multiple active, distinguishable security associations for communication devices, allowing them to pre-register and seamlessly switch between various access technologies like WiMAX and WiFi, while maintaining existing security contexts to reduce handoff latency and ensure continuous access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If existing authentication methods are used for handover between different radio access networks, then authentication can be performed, but multiple security contexts cannot be effectively maintained for multiple access technologies

Engineering Contradiction:
Improvesupport for multiple access technologiesVSAvoidmaintenance of security contexts
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security context management by creating separate, technology-specific security contexts (first security context for first access technology, second security context for second access technology) rather than using a single unified authentication mechanism. This allows each access technology to maintain its own security parameters and credentials independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements pre-registration and pre-authentication mechanisms where the communication device is authenticated in advance for multiple access technologies before actual handover occurs. Security contexts are generated and stored beforehand, enabling seamless transition without re-authentication during handover.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If a communication device switches between different access technologies, then access flexibility is improved, but handoff latency increases due to re-authentication requirements

Engineering Contradiction:
Improveaccess flexibilityVSAvoidhandoff latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs authentication and generates security contexts in advance for multiple access technologies before handover is needed. The device is pre-registered with the network for both first and second access technologies, so when handover occurs, the device can immediately use pre-established security contexts without time-consuming re-authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuous security contexts across access technology transitions. By preserving the first security context while generating a second security context, the device ensures uninterrupted access and eliminates authentication gaps during handover, making the transition seamless and latency-free.

Inventive Principle:
Principle #20Continuity of useful action

3Ease of operation

If multiple security contexts are generated for multiple access technologies, then seamless handover is enabled, but device and network complexity increases

Engineering Contradiction:
Improveseamless handoverVSAvoidsecurity context management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent uses a universal authentication framework (EAP - Extensible Authentication Protocol) that works across multiple access technologies. The same EAP authentication mechanism is applied for both first and second access technologies, providing a consistent multi-functional approach that simplifies implementation despite supporting multiple technologies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an authentication server as an intermediary that manages multiple security contexts. The authentication server stores and manages both the first security context and second security context, offloading the complexity of multi-context management from the communication device to a centralized network entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2471289B1Pre-registration security support in multi-technology interworking
Publication Date: 2019.09.25 ALCATEL LUCENT SA
  • EP2471289B1 patent drawingFigure 1
  • EP2471289B1 patent drawingFigure 2A
  • EP2471289B1 patent drawingFigure 2B

AI summary

Pre-registration security support in a multiple access technology environment is disclosed. For example, a method is disclosed for use in a computing device of a communication system. The communication system supports two or more access technologies for permitting a communication device to access the communication system, and at least part of a first security context is generated at the computing device for a given communication device permitting the given communication device to access the communication system via a first access technology. The method comprises generating at the computing device at least part of at least a second security context for the given communication device such that the given communication device is pre-registered to access the communication system via at least a second access technology while maintaining the first security context such that the given communication device continues to access the communication system via the first access technology and is pre-registered to subsequently access the communication system via the second access technology.