The document discusses the formal verification of security for dual connectivity in LTE, a feature developed by 3GPP that allows a terminal to connect to two base stations simultaneously. It presents a key establishment model and analyzes it using three formal verification tools—Scyther, Tamarin, and Proverif—to prove essential security properties such as secrecy, agreement, and key freshness. This is notable as it represents the first instance of using formal tools in the telecom standardization process, aiming to increase assurance before system deployment.