WWAN-WLAN Aggregation Security via PMKID Pre-establishment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of WWAN and WLAN links in LWA systems poses a challenge in ensuring secure data transmission, as existing methods lack effective security measures to protect communications between user devices and network components.

Innovation Solution

A method is introduced that involves receiving a user equipment identifier and a cryptographic key from a WWAN node, using the key as a pairwise master key (PMK), generating a PMK identifier (PMKID), and initializing a PMK security association (PMKSA) to establish a secure WLAN connection with the user equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data aggregation at RAN is implemented to improve resource utilization and system capacity, then aggregate throughput and system capacity are improved, but data security concerns arise due to transmission over both WWAN and WLAN links

Engineering Contradiction:
Improveaggregate throughputVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent establishes security associations and derives cryptographic keys before data transmission begins. The eNB pre-establishes PMKSA (Pairwise Master Key Security Association) with the WLAN access point and pre-derives PDCP (Packet Data Convergence Protocol) encryption keys for both WWAN and WLAN links, ensuring security measures are in place prior to aggregated data transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security management mechanism where the eNB acts as a central coordinator that derives and manages encryption keys for both WWAN and WLAN interfaces. The PDCP layer serves as an intermediary that applies consistent security processing to data packets regardless of which radio interface (WWAN or WLAN) is used for transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If WLAN offloading is used to increase network data capacity, then network capacity is improved, but security measures must be enhanced to protect communications over WLAN links

Engineering Contradiction:
Improvenetwork data capacityVSAvoidcommunication security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent implements a universal security framework where the same PDCP security mechanisms and key management procedures are applied to both WWAN and WLAN transmissions. The eNB uses a unified key derivation process that generates appropriate encryption keys for either interface, allowing secure multi-functional operation across different radio access technologies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent dynamically changes security parameters based on the transmission interface. Different encryption keys are derived and applied depending on whether data is transmitted over WWAN or WLAN, with the security configuration adapting to the specific interface being used while maintaining consistent security policies.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12207083B2WWAN-WLAN aggregation security
Publication Date: 2025.01.21 QUALCOMM INC
  • US12207083B2 patent drawing
  • US12207083B2 patent drawing
  • US12207083B2 patent drawing

AI summary

One feature pertains to a method for secure wireless communication at an apparatus of a network. The method includes receiving a user equipment identifier identifying a user equipment and a cryptographic key from a wireless wide area network node, and using the cryptographic key as a pairwise master key (PMK). A PMK identifier (PKMID) is generated based on the PMK and the two are stored at the network. A PMK security association is initialized by associating the PMK with at least the PMKID and an access point identifier identifying an access point of the apparatus. An association request is received that includes a PMKID from the user equipment, and it's determined that the PMKID received from the user equipment matches the PMKID stored. A key exchange is initiated with the user equipment based on the PMK to establish a wireless local area network security association with the user equipment.