Security Context Escrowing for Seamless SGW Relocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Machine Type Communication (MTC) environments with high-density UE deployments, the existing Small Data, Fast Path (SDFP) optimization does not seamlessly handle SGW relocation, leading to significant control plane radio signaling overhead and resource scarcity issues, particularly affecting power-saving and seamless handover processes.

Innovation Solution

Implementing a security context escrowing mechanism between the Serving Gateway (SGW) and the Mobility Management Entity (MME) to backup and restore the UE's security context, eliminating the need for explicit re-authentication and signaling during SGW relocation, thus ensuring seamless gateway relocation and reducing radio resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If SDFP optimization is implemented to reduce signaling for small data communications, then radio resource efficiency is improved, but seamless handling of SGW relocation cannot be achieved

Engineering Contradiction:
Improveradio resource usageVSAvoidseamless SGW relocation
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The security context is escrowed (stored) in advance in the MME before SGW relocation occurs. This preliminary storage of authentication data enables the target SGW to quickly restore security contexts without requiring re-authentication signaling, thus resolving the contradiction between reduced radio signaling and seamless relocation handling.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If explicit re-authentication is performed during SGW relocation, then security is maintained, but control plane radio signaling overhead increases

Engineering Contradiction:
Improvesecurity context integrityVSAvoidcontrol plane radio signaling
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The authentication and security context management functions are extracted from the radio access network and relocated to the core network (MME). By escroweing security contexts in the MME, the system separates security management from the radio interface, eliminating the need for re-authentication signaling over the air while maintaining security integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The MME acts as an intermediary that stores and manages security contexts escrowed from the SGW. During SGW relocation, the MME provides the necessary security context information to the target SGW, mediating between the old and new gateways without requiring direct re-authentication between the UE and the new SGW, thus reducing radio signaling overhead.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security context escrowing is implemented, then seamless SGW relocation is achieved, but network node complexity increases

Engineering Contradiction:
Improveseamless connectivity during relocationVSAvoidMME functionality
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The MME, which already performs mobility management and authentication functions, is extended to include security context escrowing capabilities. By making the MME multi-functional (handling both traditional mobility management and security context storage/management), the system achieves seamless SGW relocation without adding dedicated new network nodes, thus limiting the increase in overall network complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3453205B1Security context escrowing
Publication Date: 2022.04.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3453205B1 patent drawingFigure 1
  • EP3453205B1 patent drawingFigure 2
  • EP3453205B1 patent drawingFigure 3

AI summary

Methods, systems, and computer program products for security context escrowing are provided herein. According to one aspect, a method of operation of a network node for a telecommunications network comprises storing security context information associated with a small data, fast path connection between a wireless device and a first gateway that is serving the wireless device, determining a change in the gateway that is serving the wireless device from the first gateway to a second gateway, and, in response to determining the change, providing the stored security context information to the second gateway for use with the wireless device.