Seamless Handover Key Generation for Trusted Non-3GPP Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face challenges in seamless mobility between trusted non-3GPP access points, leading to interruptions in service when a user equipment (UE) moves between access points connected to the same gateway function, as they require re-authentication and disconnect from the source access point before reconnecting to the target access point.
Innovation Solution
The system determines a change of connection from a source access point to a target access point, generates an access point key based on an indication that the associated gateway function is the same for both points, and secures communications using this key, allowing the UE to move without full authentication and maintain continuous network connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If re-authentication is performed when user equipment moves between access points, then security is maintained, but service continuity is interrupted and authentication latency increases
Solution Approach 1:
The gateway function pre-establishes security contexts and keys for multiple access points before the user equipment needs to move between them. When mobility occurs, the system can quickly switch between pre-configured access points without performing full re-authentication, thus maintaining security while reducing authentication latency.
Solution Approach 2:
The gateway function acts as an intermediary that manages security contexts between the user equipment and multiple access points. It maintains a database of pre-established keys and security parameters, allowing the system to verify user identity and grant access without requiring full re-authentication during handovers, thereby reducing latency while preserving security.
2Reliability
If full authentication is performed for each access point connection, then security is ensured, but network resources are consumed and service interruption occurs
Solution Approach 1:
The gateway function performs authentication and key establishment in advance for multiple access points during an initial registration process. This preliminary action creates a pool of valid security contexts that can be quickly activated during mobility events, ensuring security without requiring full authentication procedures for each connection change, thus maintaining service continuity.
Solution Approach 2:
During access point handovers, the system discards the need for full re-authentication by recovering and reusing pre-established security keys and contexts from the gateway function's database. This allows the system to maintain security by relying on previously validated authentication data rather than performing redundant authentication procedures, thereby improving productivity and service continuity.
3Reliability
If connection change requires disconnection from source access point first, then authentication control is maintained, but mobility experience deteriorates
Solution Approach 1:
The gateway function pre-establishes security contexts for multiple access points before the user equipment needs to move. When mobility occurs, the system can immediately activate a pre-configured target access point without first disconnecting from the source, as the security infrastructure is already in place. This preliminary preparation enables seamless handovers that maintain authentication control while significantly improving mobility experience.
Solution Approach 2:
The system maintains continuous network connectivity during handovers by using pre-established security contexts that allow the user equipment to remain connected to the network throughout the transition. The gateway function continuously manages security contexts for multiple access points, ensuring that authentication control is maintained while the user equipment experiences uninterrupted service during mobility, thus improving ease of operation.
Data Source
AI summary
There is provided an apparatus comprising means for determining a change of connection at a user equipment from a source access point to a target access point, and means for receiving, from the target access point, an indication that an associated gateway function is the same for the source access point and the target access point. The apparatus also comprising means for generating an access point key based on the received indication from the target access point, and means for securing communications with the target access point using the generated access point key.


