UE Security Context Reuse for Faster Multiple Network Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems require time-consuming full authentication of user equipment (UE) every time it registers with a new wireless network, which is inefficient for UE registered with multiple networks.

Innovation Solution

The UE reuses a previously established key to establish a security context with a new network by deriving a key identifier and key count, bypassing the need for a primary authentication process, thus allowing efficient multiple network registrations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full authentication is performed every time UE registers with a new wireless network, then security context establishment is reliable, but registration time and resource consumption increase significantly

Engineering Contradiction:
Improvesecurity context establishmentVSAvoidregistration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and key establishment in advance during initial network registration, storing the security context locally in the UE. When the UE later registers with new networks, it retrieves and reuses the pre-established security context instead of performing full authentication again, thus eliminating the time loss while maintaining security reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal security context that can be reused across multiple different wireless networks and access types (3GPP and non-3GPP). This single authentication result serves multiple registration purposes, allowing the UE to efficiently register with various networks without repeating the full authentication process each time

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If full authentication is performed every time UE registers with a new wireless network, then security context is securely established, but network resource consumption increases

Engineering Contradiction:
Improvesecurity context establishmentVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs the computationally intensive authentication and key derivation operations in advance during initial registration, storing the results locally. Subsequent network registrations simply retrieve and apply the pre-computed security context, dramatically reducing the processing energy and network resource consumption for each registration event while maintaining secure context establishment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates copies of the security context (authentication results, keys, and related parameters) and stores them in the UE's local memory. These copied security contexts are then reused for multiple network registrations, eliminating the need to repeatedly perform full authentication and thereby reducing both energy consumption and network resource usage while maintaining security

Inventive Principle:
Principle #26Copying

Data Source

PatentEP4271121B1Method and apparatus for multiple registrations
Publication Date: 2025.12.31 QUALCOMM INC
  • EP4271121B1 patent drawingFigure 1
  • EP4271121B1 patent drawingFigure 2A
  • EP4271121B1 patent drawingFigure 2B

AI summary

A user device having a security context with a first network based on a first key may establish a security context with a second network. In a method, the user device may generate a key identifier based on the first key and a network identifier of the second network. The user device may forward the key identifier to the second network for forwarding to the first network by the second network to enable the first network to identify the first key at the first network. The user device may receive a key count from the second network. The key count may be associated with a second key forwarded to the second network from the first network. The user device may generate the second key based on the first key and the received key count thereby establishing a security context between the second network and the user device.