Seamless Handover Key Generation for Trusted Non-3GPP Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in seamless mobility between trusted non-3GPP access points, leading to interruptions in service when a user equipment (UE) moves between access points connected to the same gateway function, as they require re-authentication and disconnect from the source access point before reconnecting to the target access point.

Innovation Solution

The system determines a change of connection from a source access point to a target access point, generates an access point key based on an indication that the associated gateway function is the same for both points, and secures communications using this key, allowing the UE to move without full authentication and maintain continuous network connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If re-authentication is performed when user equipment moves between access points, then security is maintained, but service continuity is interrupted and authentication latency increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The gateway function pre-establishes security contexts and keys for multiple access points before the user equipment needs to move between them. When mobility occurs, the system can quickly switch between pre-configured access points without performing full re-authentication, thus maintaining security while reducing authentication latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway function acts as an intermediary that manages security contexts between the user equipment and multiple access points. It maintains a database of pre-established keys and security parameters, allowing the system to verify user identity and grant access without requiring full re-authentication during handovers, thereby reducing latency while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full authentication is performed for each access point connection, then security is ensured, but network resources are consumed and service interruption occurs

Engineering Contradiction:
ImprovesecurityVSAvoidservice continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The gateway function performs authentication and key establishment in advance for multiple access points during an initial registration process. This preliminary action creates a pool of valid security contexts that can be quickly activated during mobility events, ensuring security without requiring full authentication procedures for each connection change, thus maintaining service continuity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

During access point handovers, the system discards the need for full re-authentication by recovering and reusing pre-established security keys and contexts from the gateway function's database. This allows the system to maintain security by relying on previously validated authentication data rather than performing redundant authentication procedures, thereby improving productivity and service continuity.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If connection change requires disconnection from source access point first, then authentication control is maintained, but mobility experience deteriorates

Engineering Contradiction:
Improveauthentication controlVSAvoidmobility experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The gateway function pre-establishes security contexts for multiple access points before the user equipment needs to move. When mobility occurs, the system can immediately activate a pre-configured target access point without first disconnecting from the source, as the security infrastructure is already in place. This preliminary preparation enables seamless handovers that maintain authentication control while significantly improving mobility experience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous network connectivity during handovers by using pre-established security contexts that allow the user equipment to remain connected to the network throughout the transition. The gateway function continuously manages security contexts for multiple access points, ensuring that authentication control is maintained while the user equipment experiences uninterrupted service during mobility, thus improving ease of operation.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20240056804A1Method, apparatus and computer program
Publication Date: 2024.02.15 NOKIA TECHNOLOGIES OY
  • US20240056804A1 patent drawing
  • US20240056804A1 patent drawing
  • US20240056804A1 patent drawing

AI summary

There is provided an apparatus comprising means for determining a change of connection at a user equipment from a source access point to a target access point, and means for receiving, from the target access point, an indication that an associated gateway function is the same for the source access point and the target access point. The apparatus also comprising means for generating an access point key based on the received indication from the target access point, and means for securing communications with the target access point using the generated access point key.