Wireless Security Model for Multiple Service Contexts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems typically support only a single subscription and credential, limiting the ability to establish multiple connectivity and service contexts over a single connectivity context, which restricts the flexibility and security of service connections.

Innovation Solution

A security model that allows multiple service contexts to be established using different credentials over a shared single connectivity context, with each service context having distinct non-access stratum (NAS) and access stratum (AS) security contexts, enabling simultaneous connections to multiple service providers through a host mobility management entity (HMME).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single connectivity context is used between UE and network, then the system maintains simplicity in connection management, but the system cannot support multiple subscriptions or service providers simultaneously

Engineering Contradiction:
Improveability to support multiple subscriptions and service providersVSAvoidconnection management structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the connection management structure by introducing multiple service contexts (ESM contexts) that can coexist within a single connectivity context (EMM context). Each service context is independently managed with its own security parameters and authentication credentials, allowing the system to support multiple subscriptions and service providers while maintaining a unified connectivity framework. This segmentation enables parallel service connections without requiring separate physical connections for each service.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal service context framework where a single connectivity context can serve multiple service providers and subscriptions simultaneously. The service context structure is designed to be multi-functional, accommodating different service types, authentication methods, and security requirements within a unified architecture. This allows the same connectivity infrastructure to support diverse services without requiring dedicated connection management for each service type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple service connections are established over a single connectivity context, then service flexibility increases, but security management complexity increases

Engineering Contradiction:
Improveservice connection flexibilityVSAvoidsecurity context management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security management by creating distinct security contexts for each service connection while maintaining a hierarchical relationship with the parent connectivity context. Each service context has its own security parameters, keys, and authentication state, allowing independent security management for each service. This segmentation enables the system to enforce different security policies for different services without compromising the overall security architecture or requiring manual configuration for each service connection.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If a one-to-one relationship is maintained between connectivity context and SIM credential, then authentication security is simplified, but the system cannot support multiple credentials simultaneously

Engineering Contradiction:
Improvemulti-credential supportVSAvoidcredential management structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the credential management structure by associating multiple service contexts with a single connectivity context, where each service context can have its own credential references. This allows the system to maintain the security benefits of credential-based authentication while supporting multiple credentials simultaneously. The service context acts as an intermediary layer that links credentials to services without requiring a separate connectivity context for each credential, thus managing complexity while enabling multi-credential support.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11729619B2Methods and apparatus for wireless communication using a security model to support multiple connectivity and service contexts
Publication Date: 2023.08.15 QUALCOMM INC
  • US11729619B2 patent drawing
  • US11729619B2 patent drawing
  • US11729619B2 patent drawing

AI summary

Aspects of the present disclosure provide for a security model for enabling multiple connectivity and service contexts while sharing a single connectivity context to establish a network connection. A context (e.g., connectivity context, service context, security context) is a set of information describing the connectivity, service, or security established between two or more entities. The connectivity context and service context may be established at different network nodes or entities. In one aspect of the disclosure, a connectivity context includes an Evolved Packet System (EPS) Mobility Management (EMM) context or both an EMM context and an EPS Session Management (ESM) context.