Deriving WLAN Security Context from WWAN Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in establishing secure associations between wireless local area networks (WLANs) and wireless wide area networks (WWANs, particularly due to delays in authentication procedures, which affect network reliability and availability.

Innovation Solution

The method involves deriving a WLAN security context from an existing WWAN security context, allowing for a low-latency secure association by using a Pairwise Master Key (PMK) generated from the WWAN key or an access security management entity (ASME) key, thereby bypassing conventional EAP authentication procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional EAP authentication procedures are used to establish secure WLAN associations, then security is maintained, but authentication delays occur affecting network reliability and availability

Engineering Contradiction:
Improvenetwork availabilityVSAvoidauthentication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by establishing the WWAN security context and deriving the PMK in advance, before the WLAN association is actually needed. The base station pre-generates security parameters and stores them, so when WLAN association is required, the authentication can proceed rapidly using the pre-computed security context, thus reducing authentication delay while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy of the security context by deriving a PMK from the WWAN security context (specifically from the ASME key or WWAN key). This derived PMK serves as a copy that can be used for WLAN authentication without requiring the original EAP authentication procedure to be executed again, thereby eliminating authentication delays while preserving security through the cryptographic derivation relationship

Inventive Principle:
Principle #26Copying

2Reliability

If conventional EAP authentication procedures are used to establish secure WLAN associations, then proper authentication is ensured, but network reliability and user experience deteriorate due to delays

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidassociation establishment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates a cryptographic copy of the authentication credentials by deriving the PMK from the WWAN security context. This derived PMK can be used directly for WLAN authentication without re-executing the full EAP procedure, thus maintaining authentication reliability while dramatically improving association establishment speed

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the authentication parameter from requiring full EAP procedure execution to using a pre-derived PMK. By transforming the authentication mechanism from a multi-step protocol exchange to a direct PMK-based authentication, the system maintains security reliability while improving association establishment speed

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2936857B1Method and device for deriving a WLAN security context from a WWAN security context
Publication Date: 2019.09.25 QUALCOMM INC
  • EP2936857B1 patent drawingFigure 1
  • EP2936857B1 patent drawingFigure 2
  • EP2936857B1 patent drawingFigure 3

AI summary

Techniques for deriving a WLAN security context from an existing WWAN security context are provided. According to certain aspects, a user equipment (UE) establishes a secure connection with a wireless wide area network (WWAN). The UE may receive from the WWAN an indication of a wireless local area network (WLAN) for which to derive a security context. The UE then derives the security context for the WLAN, based on a security context for the WWAN obtained while establishing the secure connection with the WWAN and establishes a secure connection with the WLAN using the derived security context for the WLAN. This permits the UE to establish a Robust Security Network Association (RSNA) with the WLAN while avoiding lengthy authentication procedures with an AAA server, thus speeding up the association process.