Security Agent Configuration for D2D Wireless Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless networks, particularly in LTE systems, a failure of the S1 interface between a base station and the core network can disrupt communication, leading to unavailability of security services and interrupting mission-critical communications during natural disasters or equipment failures, as the core network is unable to provide authentication and authorization services.

Innovation Solution

A method where a base station detects the failure of the S1 interface and configures a mobile station as a security agent, enabling it to authenticate other mobile stations and provide security-related services, allowing continued device-to-device communication and ensuring access to the network for critical users like emergency personnel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the core network is used to provide authentication and authorization services, then security services are available, but communication is interrupted when the S1 interface fails

Engineering Contradiction:
Improveavailability of security servicesVSAvoidcommunication continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

A security agent is introduced as an intermediary component that can perform authentication and authorization services locally at the base station when the core network is unavailable. The security agent acts as a mediator between mobile stations and the base station, enabling security functions to continue operating during S1 interface failures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The base station pre-configures a security agent with necessary security context information and credentials before the S1 interface failure occurs. This preliminary preparation allows the security agent to immediately assume authentication and authorization functions when the core network becomes unavailable, avoiding service interruption.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If device-to-device mode is enabled for continued communication, then communication continuity is maintained, but security services become unavailable without core network connection

Engineering Contradiction:
Improvecommunication continuityVSAvoidavailability of security services
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The security agent serves as a local intermediary that provides authentication and authorization services within the device-to-device communication mode. It enables security functions to operate independently of the core network while mobile stations communicate directly, resolving the contradiction between D2D communication continuity and security service availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a security agent is configured to authenticate mobile stations, then security services are maintained during S1 interface failure, but system complexity increases

Engineering Contradiction:
Improveavailability of security services during failureVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The base station automatically selects and configures a security agent from among the connected mobile stations without requiring manual intervention or complex external coordination. The selected mobile station self-assumes the security agent role, performing authentication and authorization functions locally, which maintains security services while avoiding the need for additional dedicated hardware or complex system architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3058693B1Selection and use of a security agent for device-to-device (D2D) wireless communications
Publication Date: 2020.03.18 NOKIA SOLUTIONS & NETWORKS OY
  • EP3058693B1 patent drawingFigure 1
  • EP3058693B1 patent drawingFigure 2
  • EP3058693B1 patent drawingFigure 3

AI summary

A technique is provided for receiving, by a MS from a BS a failure notification message indicating a failure of a BS-core network interface, sending, from the MS to the BS, a security agent (SA) notification including a MSID identifying the MS, a service profile identifying one or more services, and one or more user group IDs that identify one or more user groups of which the MS is a member, and receiving, by the MS from the BS, a SA configuration message including a service identification identifying at least one of the one or more services, one or more user group IDs identifying one or more user groups for which the MS has been configured as a security agent to perform the identified service, and a BS access key to allow one or more other MSs to access or establish a connection with the BS.