User Equipment Security Context Validation for Inter-RAT Mobility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face security risks when a user equipment (UE) moves from one radio access technology (RAT) to another, as the security context established in one RAT may not be sufficient for mutual authentication in the new RAT, potentially leading to unauthorized access and fraudulent network usage.

Innovation Solution

The UE determines if the existing security context is not mutually authenticated and takes unilateral actions to prevent its use in the new RAT, such as initiating a new authentication procedure, deleting the old security context, or disabling inter-RAT procedures, ensuring mutual authentication is established before allowing access to the new network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the UE re-uses the security context established in one RAT when moving to a different RAT, then the UE can maintain continuous service without re-authentication, but the network security is compromised because the security context may not be sufficient for mutual authentication in the new RAT

Engineering Contradiction:
Improveservice continuityVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the network initiate authentication procedures before the UE attempts to use a potentially insufficient security context. The network determines whether the existing security context is adequate for the target RAT and performs necessary authentication actions in advance, preventing security compromises while maintaining service continuity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the network evaluates the adequacy of the UE's security context for the target RAT and provides feedback through authentication procedures. Based on this feedback, the network either allows use of the existing context or initiates re-authentication, dynamically adjusting security measures based on actual security requirements.

Inventive Principle:
Principle #23Feedback

2Reliability

If the UE performs mutual authentication with the network in each RAT, then the network security is enhanced, but the authentication procedure becomes more complex and time-consuming

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication procedure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making the authentication approach dependent on the specific RAT context. Instead of universally requiring mutual authentication in all scenarios, the system adapts the authentication level to the local security requirements of each RAT, using full mutual authentication only when necessary while allowing simpler procedures when the security context is already adequate.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If the UE allows use of non-mutual authentication contexts in different RATs, then the ease of operation is improved, but the network is vulnerable to unauthorized access and fraudulent activities

Engineering Contradiction:
Improveinter-RAT mobilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the network as an intermediary that mediates between the UE's desire for easy inter-RAT mobility and the security requirements. The network evaluates security contexts and controls authentication procedures, acting as a mediator that allows convenient mobility while preventing unauthorized access through its security validation functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9161221B2Method, apparatus and computer program for operating a user equipment
Publication Date: 2015.10.13 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US9161221B2 patent drawing
  • US9161221B2 patent drawing
  • US9161221B2 patent drawing

AI summary

Embodiments provide a method, apparatus and computer program for operating a user equipment (UE). The method begins by determining that a valid authentication for the UE, generated with a radio network operating with a first radio access technology (RAT), is not a mutual authentication between the UE and the network operating with the first RAT. In response, the UE unilaterally takes action to prevent the valid authentication that is not a mutual authentication from being used to authenticate with a radio network operating with a second RAT that utilizes mutual authentication.