Radio Link Reestablishment via Core Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In wireless communication systems, particularly in LTE, user equipment (UE) experiencing radio link failure (RLF) cannot securely reestablish a radio communication link without access stratum (AS) security keys, posing a risk of malicious attacks, especially when using control plane signaling to transmit user plane data.
Innovation Solution
A method and system that uses a message authentication code (MAC) based on the non-access stratum (NAS) COUNT value and device identifier to authenticate the UE, allowing secure reestablishment of the radio communication link with a new radio access node, even in the absence of AS security keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a UE uses control plane signaling to transmit user plane data without establishing AS security keys, then the device complexity and setup time are reduced, but the security and reliability of radio link reestablishment are compromised
Solution Approach 1:
The patent introduces the core network node as an intermediary that performs authentication of the UE during radio link reestablishment. The core network node verifies the UE's identity and authorizes the reestablishment process, acting as a mediator between the UE and the target radio access node. This allows UEs without AS security keys to securely reestablish links through control plane signaling by delegating authentication to the core network.
2Reliability
If AS security keys are required for secure reestablishment, then the security is improved, but the reestablishment process cannot be completed by UEs using control plane signaling
Solution Approach 1:
The patent changes the authentication parameter from AS security keys to core network-based authentication using UE identity verification. Instead of requiring AS security keys at the radio access node level, the system uses core network authentication parameters (UE identity, subscription data) to enable secure reestablishment for UEs using control plane signaling. This parameter change makes the system adaptable to different UE types while maintaining security.
3Speed
If the UE attempts to reestablish connection without proper authentication, then the reestablishment speed is improved, but malicious attacks and unauthorized access become possible
Solution Approach 1:
The patent implements preliminary authentication action by having the core network node verify the UE's identity and authorize reestablishment before the UE actually reestablishes the radio link with the target access node. This preliminary security check prevents malicious attacks and unauthorized access while maintaining fast reestablishment speed, as the authentication is performed in advance during the control plane signaling process rather than during the radio link setup.
Data Source
AI summary
One feature pertains to a method that includes establishing a radio communication connection with a first radio access node (RAN) that uses control plane signaling connections to carry user plane data. The method also includes determining that the wireless communication device is experiencing radio link failure (RLF) with the first RAN and that the radio communication connection should be reestablished with a second RAN. A reestablishment request message is transmitted to the second RAN that includes parameters that enable a core network node communicatively coupled to the second RAN to authenticate the wireless communication device and allow or reject reestablishment of the radio communication connection. The parameters include at least a message authentication code (MAC) based in part on one or more bits of a non-access stratum (NAS) COUNT value maintained at the wireless communication device.


