Wireless Device LAN Handover via Access Node Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face challenges in establishing secure and seamless handovers between access nodes in local area networks, leading to service interruptions and inefficiencies in authentication processes.

Innovation Solution

The implementation of modified LAN protocols that support network-centric handover operations, using temporary security keys and fast transition parameters, enables secure communication and rapid handovers between access nodes, leveraging enhanced security protocols to trust the exchange of security information between access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication processes are used during handover between access nodes, then security is maintained, but service interruptions occur due to lengthy authentication procedures

Engineering Contradiction:
ImprovesecurityVSAvoidservice interruption duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication by establishing security contexts and authentication credentials before the actual handover occurs. The source access node prepares authentication information and forwards it to the target access node in advance, so that when handover occurs, the authentication is already complete or near-complete, eliminating service interruptions while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the source access node acts as a mediator to transfer security contexts and authentication credentials to the target access node. This intermediary process allows the target node to authenticate the wireless device quickly without requiring the device to perform full authentication procedures, thus reducing service interruption while maintaining security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full authentication procedures are performed during handover, then security is ensured, but authentication efficiency decreases due to repeated authentication processes

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies the discarding and recovering principle by allowing the source access node to discard its security context after successful handover, while the target access node recovers and utilizes the transferred authentication credentials. This eliminates the need for the wireless device to perform repeated full authentication procedures, significantly improving authentication efficiency while maintaining security through the transferred credentials.

Inventive Principle:
Principle #34Discarding and recovering

Solution Approach 2:

The patent performs preliminary authentication by establishing security contexts in advance at the source access node and transferring them to the target access node before the handover is complete. This preliminary action allows the target node to have authentication credentials ready, eliminating the need for repeated full authentication procedures and thereby improving authentication efficiency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Speed

If security information is exchanged between access nodes, then handover speed increases, but device complexity increases due to enhanced security protocols

Engineering Contradiction:
Improvehandover speedVSAvoidsecurity protocol complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent extracts the complex security information exchange process from the wireless device and relocates it to the network infrastructure (source and target access nodes). The device simply follows handover commands while the heavy lifting of security context transfer and authentication credential exchange is performed by the network elements, thereby increasing handover speed without significantly increasing device complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses the source access node as an intermediary to handle the complex security information exchange with the target access node. The source node prepares and forwards security contexts, authentication credentials, and related parameters to the target node, shielding the wireless device from the complexity of these exchanges while enabling fast handover through pre-established security relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3494759B1Techniques for establishing a secure connection between a wireless device and a local area network via an access node
Publication Date: 2021.03.31 QUALCOMM INC
  • EP3494759B1 patent drawingFigure 1
  • EP3494759B1 patent drawingFigure 2
  • EP3494759B1 patent drawingFigure 3~4

AI summary

Methods, systems, and devices for wireless communication are described. In one method, a wireless device may establish a connection with an access node (AN) of a local area network (LAN). The wireless device may also determine to perform an authentication. The wireless device may further receive an indication, as part of the authentication, of a protocol end point for the authentication as being a non-access stratum (NAS) layer or a radio resource control (RRC) layer. In another method, an AN may establish a connection with a wireless device. The AN may determine the wireless device determined to perform an authentication with an authenticator included in the AN. The AN may further indicate, as part of the authentication, a protocol end point for the authentication as being the NAS layer or the RRC layer.