Unified Authentication Path for Small Cell–Wi-Fi Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In current 3GPP inter-working architectures, multi-RAT UEs require separate authentication paths via MME and 3GPP AAA Server, leading to redundant authentication procedures and increased burden on the core network during handovers between LTE and Wi-Fi networks.

Innovation Solution

A unified authentication path is established through the MME for both Small Cell and Wi-Fi networks, eliminating the need for separate paths and reducing redundant authentication by integrating the 3GPP AAA Server, and implementing fast re-authentication procedures for efficient handovers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication paths via MME and 3GPP AAA Server are used for LTE and Wi-Fi networks, then authentication can be performed for each access type, but redundant authentication procedures and increased burden on the core network occur

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication path complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the separate authentication paths for LTE and Wi-Fi into a unified authentication path through the MME. The MME is enhanced to handle both E-UTRAN and TWAN authentication, consolidating what were previously two separate authentication workflows into one unified process, thereby reducing redundancy and core network burden

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The MME is extended to perform multiple authentication functions - serving as the authentication entity for both E-UTRAN (LTE) access and TWAN (Wi-Fi) access. This multi-functional capability eliminates the need for separate authentication paths and reduces the overall complexity of the authentication architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If separate authentication paths are maintained, then specific authentication procedures can be optimized for each RAT, but handover between LTE and Wi-Fi requires redundant authentication messages

Engineering Contradiction:
Improvehandover efficiencyVSAvoidauthentication time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication through the MME before handover occurs. When a UE attaches to the network, the MME performs authentication and establishes security contexts that can be reused during handover between E-UTRAN and TWAN, eliminating the need for redundant authentication messages during handover

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The unified authentication path enables continuous authentication state maintenance during handover between LTE and Wi-Fi. The MME preserves authentication contexts and security parameters, allowing the authentication process to continue seamlessly without interruption or redundancy, thereby improving handover efficiency and reducing authentication time

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If the P-GW handles inter-system handover, then complete architecture control is maintained, but huge burden is placed on the Mobile Core Network

Engineering Contradiction:
Improvehandover controlVSAvoidcore network processing burden
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent segments the handover control functions by separating authentication/signaling handling from data plane routing. The MME handles authentication and control plane signaling for both E-UTRAN and TWAN, while the P-GW maintains its data plane routing functions. This segmentation distributes the processing burden appropriately, reducing the load on the core network while maintaining handover control

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3304856B1Unified authentication for integrated small cell and wi-fi networks
Publication Date: 2025.09.17 IPLA HLDG INC
  • EP3304856B1 patent drawingFigure 1
  • EP3304856B1 patent drawingFigure 2
  • EP3304856B1 patent drawingFigure 3

AI summary

Multi-RAT UEs currently have 2 independent paths to authenticate with HSS (either via the MME or the 3GPP AAA Server causing repeated authentication messages to HSS. The use of one unified authentication path between the UE and HSS for Small Cell and Wi-Fi authentication is described. First, a new 3GPP EPC-TWAN interworking architecture has the MME manage all the authentication requests from multi-RAT UEs. Second, new unified authentication procedures are added, which allow the ISWN-based multi-RAT UE to be authenticated directly with the HSS, irrespective of its current access network (TWAN or HeNB). Third, new fast re-authentication procedures for Inter-RAT handover scenarios are done. Finally, the needed extensions to the various standard protocol messages to execute the authentication procedures are described.