Unified Authentication Path for Small Cell–Wi-Fi Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In current 3GPP inter-working architectures, multi-RAT UEs require separate authentication paths via MME and 3GPP AAA Server, leading to redundant authentication procedures and increased burden on the core network during handovers between LTE and Wi-Fi networks.
Innovation Solution
A unified authentication path is established through the MME for both Small Cell and Wi-Fi networks, eliminating the need for separate paths and reducing redundant authentication by integrating the 3GPP AAA Server, and implementing fast re-authentication procedures for efficient handovers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication paths via MME and 3GPP AAA Server are used for LTE and Wi-Fi networks, then authentication can be performed for each access type, but redundant authentication procedures and increased burden on the core network occur
Solution Approach 1:
The patent merges the separate authentication paths for LTE and Wi-Fi into a unified authentication path through the MME. The MME is enhanced to handle both E-UTRAN and TWAN authentication, consolidating what were previously two separate authentication workflows into one unified process, thereby reducing redundancy and core network burden
Solution Approach 2:
The MME is extended to perform multiple authentication functions - serving as the authentication entity for both E-UTRAN (LTE) access and TWAN (Wi-Fi) access. This multi-functional capability eliminates the need for separate authentication paths and reduces the overall complexity of the authentication architecture
2Productivity
If separate authentication paths are maintained, then specific authentication procedures can be optimized for each RAT, but handover between LTE and Wi-Fi requires redundant authentication messages
Solution Approach 1:
The patent implements preliminary authentication through the MME before handover occurs. When a UE attaches to the network, the MME performs authentication and establishes security contexts that can be reused during handover between E-UTRAN and TWAN, eliminating the need for redundant authentication messages during handover
Solution Approach 2:
The unified authentication path enables continuous authentication state maintenance during handover between LTE and Wi-Fi. The MME preserves authentication contexts and security parameters, allowing the authentication process to continue seamlessly without interruption or redundancy, thereby improving handover efficiency and reducing authentication time
3Reliability
If the P-GW handles inter-system handover, then complete architecture control is maintained, but huge burden is placed on the Mobile Core Network
Solution Approach 1:
The patent segments the handover control functions by separating authentication/signaling handling from data plane routing. The MME handles authentication and control plane signaling for both E-UTRAN and TWAN, while the P-GW maintains its data plane routing functions. This segmentation distributes the processing burden appropriately, reducing the load on the core network while maintaining handover control
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Multi-RAT UEs currently have 2 independent paths to authenticate with HSS (either via the MME or the 3GPP AAA Server causing repeated authentication messages to HSS. The use of one unified authentication path between the UE and HSS for Small Cell and Wi-Fi authentication is described. First, a new 3GPP EPC-TWAN interworking architecture has the MME manage all the authentication requests from multi-RAT UEs. Second, new unified authentication procedures are added, which allow the ISWN-based multi-RAT UE to be authenticated directly with the HSS, irrespective of its current access network (TWAN or HeNB). Third, new fast re-authentication procedures for Inter-RAT handover scenarios are done. Finally, the needed extensions to the various standard protocol messages to execute the authentication procedures are described.