Deriving WLAN Security Context from WWAN Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face challenges in establishing secure associations between wireless local area networks (WLANs) and wireless wide area networks (WWANs, particularly due to delays in authentication procedures, which affect network reliability and availability.
Innovation Solution
The method involves deriving a WLAN security context from an existing WWAN security context, allowing for a low-latency secure association by using a Pairwise Master Key (PMK) generated from the WWAN key or an access security management entity (ASME) key, thereby bypassing conventional EAP authentication procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional EAP authentication procedures are used to establish secure WLAN associations, then security is maintained, but authentication delays occur affecting network reliability and availability
Solution Approach 1:
The patent performs preliminary actions by establishing the WWAN security context and deriving the PMK in advance, before the WLAN association is actually needed. The base station pre-generates security parameters and stores them, so when WLAN association is required, the authentication can proceed rapidly using the pre-computed security context, thus reducing authentication delay while maintaining security
Solution Approach 2:
The patent creates a copy of the security context by deriving a PMK from the WWAN security context (specifically from the ASME key or WWAN key). This derived PMK serves as a copy that can be used for WLAN authentication without requiring the original EAP authentication procedure to be executed again, thereby eliminating authentication delays while preserving security through the cryptographic derivation relationship
2Reliability
If conventional EAP authentication procedures are used to establish secure WLAN associations, then proper authentication is ensured, but network reliability and user experience deteriorate due to delays
Solution Approach 1:
The patent creates a cryptographic copy of the authentication credentials by deriving the PMK from the WWAN security context. This derived PMK can be used directly for WLAN authentication without re-executing the full EAP procedure, thus maintaining authentication reliability while dramatically improving association establishment speed
Solution Approach 2:
The patent changes the authentication parameter from requiring full EAP procedure execution to using a pre-derived PMK. By transforming the authentication mechanism from a multi-step protocol exchange to a direct PMK-based authentication, the system maintains security reliability while improving association establishment speed
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques for deriving a WLAN security context from an existing WWAN security context are provided. According to certain aspects, a user equipment (UE) establishes a secure connection with a wireless wide area network (WWAN). The UE may receive from the WWAN an indication of a wireless local area network (WLAN) for which to derive a security context. The UE then derives the security context for the WLAN, based on a security context for the WWAN obtained while establishing the secure connection with the WWAN and establishes a secure connection with the WLAN using the derived security context for the WLAN. This permits the UE to establish a Robust Security Network Association (RSNA) with the WLAN while avoiding lengthy authentication procedures with an AAA server, thus speeding up the association process.