Terminal Security Context Distinction for Multi-Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of evolving radio access technologies, terminals face challenges in securely accessing wireless networks using different technologies, as existing security contexts are not effectively distinguished, leading to confusion in selecting the appropriate security context for communication, especially when key identifiers from different networks are the same.

Innovation Solution

The proposed solution involves a terminal maintaining multiple security contexts with distinct information, such as key identifiers and access technologies, to determine the appropriate security context based on the target network, ensuring correct access and communication security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the terminal uses the same key identifier from different networks, then the key management is simplified, but the terminal cannot distinguish which security context to select for different networks

Engineering Contradiction:
Improvekey management complexityVSAvoidsecurity context selection
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent segments the security context identification by introducing distinct first information (such as first indication information or first identification information) into each security context. This allows the terminal to differentiate between security contexts from different networks even when key identifiers are identical, resolving the contradiction between simplified key management and accurate security context selection.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the terminal maintains multiple security contexts with different first information, then the terminal can accurately select security contexts for different networks, but the security context structure becomes more complex

Engineering Contradiction:
Improvesecurity context selection accuracyVSAvoidsecurity context structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces first information (such as first indication information or first identification information) as an intermediary element within each security context. This intermediary provides the necessary differentiation without requiring complex external management systems, allowing accurate security context selection while maintaining a manageable security context structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If the terminal accesses multiple networks with different access technologies, then the network compatibility is improved, but the terminal faces confusion in selecting appropriate security contexts when key identifiers are the same

Engineering Contradiction:
Improvenetwork access compatibilityVSAvoidsecurity context selection reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by introducing network-specific first information into each security context. This allows the terminal to accurately identify and select the appropriate security context for each specific network access scenario, ensuring reliable security context selection across multiple networks with different access technologies.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11622268B2Secure communication method and secure communications apparatus
Publication Date: 2023.04.04 HUAWEI TECH CO LTD
  • US11622268B2 patent drawing
  • US11622268B2 patent drawing
  • US11622268B2 patent drawing

AI summary

A secure communication method and a secure communications apparatus related to the field of communications technologies and applied to a terminal. The terminal has a first security context and a second security context, the first security context is used by the terminal to communicate with a first network, the second security context is used by the terminal to communicate with a second network, and the first security context and the second security context include different first information.