Method and system for performing pre-switching security management during switching between communication systems

By introducing a freshness parameter isolation mechanism between 5G and 4G systems, the security risks during handover between mobile communication systems are resolved. A complete 4G security key system is established before handover, which improves the security and reliability between systems and reduces the handover failure rate and the risk of identity exposure.

CN121888243APending Publication Date: 2026-04-17JIANGNAN INFORMATION SECURITY (BEIJING) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JIANGNAN INFORMATION SECURITY (BEIJING) TECH CO LTD
Filing Date
2025-12-25
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

When switching between mobile communication systems, existing technologies cannot effectively isolate the exclusive parameters of the old and new systems, which threatens the security of the key system. Especially during the switch from 5G to 4G, the old system may obtain random values ​​from the new system or the new system may retain traces of the old system, increasing security risks.

Method used

By introducing a first freshness parameter and a second freshness parameter, parameters are generated and transmitted in the 5G and 4G systems respectively. TLV encapsulation is used to achieve parameter isolation, ensuring that each system can only parse its own parameters and preventing the leakage of sensitive information. Before handover, the user equipment generates a complete 4G security key system through a key derivation function, and destroys the intermediate key after handover.

Benefits of technology

It enables the establishment of a complete 4G security key system before the 5G to 4G handover, preventing reverse leakage of keys, improving the security and reliability of the handover process, reducing the handover failure rate and the risk of identity exposure, and ensuring the security and continuity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121888243A_ABST
    Figure CN121888243A_ABST
Patent Text Reader

Abstract

The invention provides a method and system for security management before switching between communication systems, and the method comprises the steps: a source side core network control plane network element generates a first intermediate master key through a key derivation function based on a second communication system core key and a first freshness parameter, the first freshness parameter is only generated in the second communication system and is transmitted to the user equipment, and the first communication system cannot acquire the first freshness parameter; the source side core network control plane network element sends the first intermediate master key to the target side core network control plane network element, and the transmission of the first intermediate master key does not carry any second communication system core key; the target side core network control plane network element generates a second master key through the same key derivation function based on the first intermediate master key and a second freshness parameter, the second freshness parameter is generated by the target side core network control plane network element and is only transmitted to the UE, and the second communication system cannot acquire the second freshness parameter.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology, and in particular to a method and system for performing pre-switching security management during handover between communication systems. Background Technology

[0002] The handover from a second mobile communication system to a first, such as the interoperability scenario from 5G to 4G, is a critical area for ensuring seamless connectivity for users across different network coverage areas. This process directly relates to the continuity and reliability of communication services, especially the need for safe and stable handovers when network signal strength changes. With the widespread deployment of 5G networks, user equipment frequently needs to switch between 5G and 4G systems, requiring security mechanisms that can adapt to the differences in characteristics between different generations of systems to maintain the security of the entire communication process.

[0003] Existing methods for handling such handovers primarily rely on core keys managed independently by each system, which prevents direct sharing of key information between the new and old systems. While such independent management is effective within a single system, it exposes a series of potential risks when cross-system handovers are involved. This is because the old system may have access to some information related to the new system, while the new system may retain traces of the old system, thereby increasing security vulnerabilities.

[0004] The core technical challenge lies in effectively isolating the unique parameters of the old and new systems. These parameters are unique random values ​​within each system, used to ensure the uniqueness and security of the keys. If these unique parameters are obtained by the other system during the handover process—for example, when switching from 5G to 4G—the 4G system, if it obtains the 5G-specific random values, could potentially reverse-engineer the 5G core key. Conversely, if the 5G system retains the 4G-specific random values, these could be used to trace the previous keys. This potential cross-exposure of parameters directly threatens the independent protection of the key systems before and after the handover, allowing one system to reverse-engineer and leak the key foundation of the other.

[0005] Therefore, establishing a complete 4G security key system before the switchover, while strictly preventing the old system from obtaining the new system's exclusive parameters during the switchover process, and preventing the new system from obtaining the old system's exclusive parameters, has become a key issue in ensuring the security of cross-generational interoperability.

[0006] like Figure 8The diagram illustrates the spatial relationship between the coverage areas and overlapping areas of 5G and 4G networks. On the left is the 5G base station (gNB), whose coverage area is represented by a dashed circle with a radius of R1, smaller than the 4G network coverage. On the right is the 4G base station (eNB), whose coverage area is represented by a solid circle with a radius of R2, larger than the 4G network coverage. The coverage areas of the two base stations overlap; this overlapping area is the network handover trigger area, indicated by a diagonal line. When a user equipment (UE) moves within this overlapping area (in the direction of movement indicated by the dashed arrow in the diagram), a handover operation between the 5G and 4G networks is triggered. The diagram also shows an edge computing node deployed near the 5G base station, which performs edge computing tasks and supports low-latency service processing. Based on this network architecture, the technical solution of this invention optimizes handover decisions and resource allocation strategies to ensure service continuity and user experience quality when the UE moves between networks. Summary of the Invention

[0007] This invention provides a method and system for pre-handover security management during handover between communication systems. Specifically, it provides a security management method for handover from a second mobile communication system to a first mobile communication system, mainly including: The source-side core network control plane element generates a first intermediate master key based on the second mobile communication system core key and a first freshness parameter through a key derivation function. The first freshness parameter is generated only within the second mobile communication system and transmitted to the user equipment; the first mobile communication system cannot obtain the first freshness parameter. The source-side core network control plane element sends the first intermediate master key to the target-side core network control plane element. The transmission of the first intermediate master key does not carry any second mobile communication system core key. The target-side core network control plane element generates a second master key based on the first intermediate master key and the second freshness parameter through the same key derivation function. The second freshness parameter is generated by the target-side core network control plane element and transmitted only to the user equipment; the second mobile communication system cannot obtain the second freshness parameter. Before actually accessing the first mobile communication system, the user equipment receives the first freshness parameter and derives the first intermediate master key based on the second mobile communication system core key. Then, after receiving the second freshness parameter, it derives the second master key based on the first intermediate master key, thus ensuring that the user equipment has a complete first mobile communication system security key system when accessing the first mobile communication system. Furthermore, the first freshness parameter includes: a downlink count of the second mobile communication system non-access stratum or a random number on the second mobile communication system side, which is transmitted to the user equipment through the second mobile communication system access network. The target-side core network control plane network element and the first mobile communication system access network cannot parse the actual value of the first freshness parameter. The second freshness parameter includes: a uplink count of the first mobile communication system non-access stratum or a partial static identifier of the user equipment, which is transparently transmitted to the user equipment through the source-side core network control plane network element and the second mobile communication system access network. The source-side core network control plane network element only transmits the actual value of the second freshness parameter without parsing it. Furthermore, the key derivation function includes: a key derivation function defined by the 3GPP standard, using a first function code when generating the first intermediate master key, and using a second function code different from the first function code when generating the second master key. Furthermore, the first intermediate master key includes: both the first intermediate master key and the second master key are 256 bits long. The target-side core network control plane network element derives the first mobile communication system non-access stratum encryption key, the non-access stratum integrity key, and the access stratum core key based on the second master key. Furthermore, the first freshness parameter includes: the first freshness parameter is encapsulated in a tag length value format, the tag value is a value specifically for identifying the second mobile communication system, and the target-side core network control plane network element directly transmits the value after recognizing the tag without being able to obtain the actual content of the parameter; the second freshness parameter is encapsulated in a tag length value format, the tag value is a value specifically for identifying the first mobile communication system, and the source-side core network control plane network element only transmits the value without parsing the actual content of the parameter.

[0008] like Figure 3As shown, the first and second freshness parameters are encapsulated using TLV (Type-Length-Value) format to achieve secure isolation during cross-system transmission. For the first freshness parameter, its TLV structure has a tag (Type) field set to identify a 5G-specific value, a length field indicating the byte length of the value field, and a value field containing freshness information such as NAS downlink count or random number. When this encapsulated parameter is transmitted in the 5G domain (AMF and 5G access network), it can be parsed normally and its actual content can be obtained. However, when this parameter is transmitted to the 4G domain (MME and 4G access network), because the tag value is identified as 5G-specific, the target MME and 4G access network recognize the tag and either pass it through or discard it directly, unable to obtain the actual content of the parameter, thus achieving parameter isolation.

[0009] For the second freshness parameter, its TLV structure has a tag field set to identify a 4G-specific value, and the value field contains information such as NAS uplink count or UE identifier. When this parameter is transmitted in the 4G domain, it can be normally parsed by the MME and 4G access network; however, when transmitted to the 5G domain, the source-side AMF and 5G access network only transmit it transparently without parsing the actual content of the parameter. Through this differentiated tagging mechanism based on TLV encapsulation, this invention ensures that each system can only parse and identify its own proprietary parameters, and transmits or discards parameters from other systems, thereby effectively preventing sensitive freshness parameters from being obtained by unauthorized systems and improving the security and isolation of cross-generational communication.

[0010] like Figure 4 As shown, the first freshness parameter and the second freshness parameter adopt an isolated transmission mechanism during the 5G-4G cross-system handover process to ensure that different network domains can only obtain and parse parameters belonging to their own systems, thereby preventing the leakage of sensitive freshness information.

[0011] Specifically, the transmission path of the first freshness parameter is as follows: after the source-side AMF generates the parameter, it is transmitted to the gNB via the NG interface, and the gNB then forwards the parameter to the UE via the NR-Uu interface. During this transmission process, the AMF and gNB, as 5G network entities, can parse and identify the first freshness parameter to obtain its actual content. However, the target-side MME, as a 4G network entity, uses a 5G-specific tag to encapsulate the first freshness parameter (see...). Figure 3 The MME was unable to parse this parameter, thus achieving the isolation and protection of the 4G domain by the first freshness parameter.

[0012] The transmission path of the second freshness parameter is as follows: After the target-side MME generates the parameter, it is transmitted to the source-side AMF via the N26 interface. The AMF then transmits the parameter to the gNB via the NG interface, and the gNB further transmits it to the UE via the NR-Uu interface. During this transmission process, the MME, as a 4G network entity, can parse the actual content of the second freshness parameter, while the source-side AMF and gNB, as 5G network entities, only perform the transmission operation and do not parse the actual content of the parameter. This is because the second freshness parameter is encapsulated using a 4G dedicated tag. After the 5G network entity recognizes this tag, it only transmits it without parsing it, thus achieving isolation and protection of the second freshness parameter from the 5G domain.

[0013] Through the aforementioned isolation transmission mechanism, this invention ensures that the first freshness parameter is visible and available only within the 5G domain, and the second freshness parameter is visible and available only within the 4G domain. Each network domain either transmits or discards parameters outside its own domain, effectively preventing the risk of freshness parameter leakage during cross-system handover and improving the security and isolation of key derivation. Furthermore, before the user equipment actually accesses the first mobile communication system, the process includes: the user equipment completing the derivation of the first intermediate master key and the second master key while still maintaining a connection with the access network of the second mobile communication system; the user equipment returning a key synchronization confirmation signal to the access network of the second mobile communication system; and after the handover is completed, the source-side core network control plane element, the target-side core network control plane element, and the user equipment destroy the first intermediate master key, retaining only the second master key and its derived keys. Furthermore, the second mobile communication system is a 5G system, the first mobile communication system is a 4G system, the source-side core network control plane element is an access and mobility management function entity, the target-side core network control plane element is a mobility management entity, and the core key of the second mobile communication system is selected from at least one of the authentication anchor key and the access and mobility management function binding key.

[0014] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects: This invention discloses a security management method before switching from a 5G system to a 4G system. In 5G to 4G interoperability switching scenarios, to address the security issues of the inability to directly share core keys between the old and new systems and the need to prevent the old system from reverse-engineering the new system's root key, this invention introduces a first freshness parameter and a second freshness parameter, which are only generated and transmitted within their respective systems, to achieve phased key derivation. The source-side AMF generates a first intermediate master key based on the 5G core key and the first freshness parameter, which is only available to the 5G system, and securely forwards it to the target MME. The MME then combines this with the second freshness parameter, which is only available to the 4G system, to generate the final 4G master key. User equipment synchronously completes the same derivation process, thereby establishing a complete 4G secure key system before the switch. Simultaneously, the freshness parameter is transmitted in isolation using a dedicated tag, ensuring that the old system cannot obtain the new system's parameters, and the new system cannot obtain the old system's parameters, avoiding the risk of reverse key leakage. After the switch is completed, the intermediate key is promptly destroyed to further enhance security. This invention achieves forward and backward security assurance, supports efficient and seamless switching, and enhances the security of interoperability between different generations of mobile communication systems.

[0015] To facilitate understanding of this invention, key terms are defined below: First mobile communication system: refers to the previous generation mobile communication system, such as the 4G LTE system; Second mobile communication system: refers to the next generation mobile communication system, such as the 5G NR system; Source-side core network control plane element: refers to the core network control plane entity of the handover initiator, which is the Access and Mobility Management Function (AMF) in the 5G→4G handover scenario; Target-side core network control plane element: refers to the core network control plane entity of the handover receiver, which is the Mobility Management Entity (MME) in the 5G→4G handover scenario; First freshness parameter: a freshness value generated by the source-side core network control plane element and transmitted only to the user equipment, used for key derivation; the target side cannot parse its actual value; Second freshness parameter: generated by the target-side core network control plane element and transparently transmitted to the user from the source side. The device's freshness value is only forwarded by the source side without parsing its content; the first intermediate master key is a temporary key generated by a key derivation function based on the core key of the second mobile communication system and the first freshness parameter, used for subsequent derivation of the target system key, and destroyed immediately after the switch is completed; the second master key is the target system master key generated based on the first intermediate master key and the second freshness parameter, used to activate the security context of the first mobile communication system; security activation refers to the process by which the target side generates a non-access stratum encryption key, an integrity key, and an access stratum key after completing the derivation of the second master key, and enables the security protection mechanism. Attached Figure Description

[0016] Figure 1 This is a flowchart of a security management method for switching from a second mobile communication system to a first mobile communication system according to the present invention.

[0017] Figure 2 This is a schematic diagram of the key derivation chain of the present invention.

[0018] Figure 3 This is a schematic diagram of the TLV parameter encapsulation format of the present invention.

[0019] Figure 4 This is a schematic diagram of the isolated transmission path for the freshness parameter of this invention.

[0020] Figure 5 This is a comparison chart showing the security and timeliness of the present invention and traditional switching schemes.

[0021] Figure 6 This is a key lifecycle state transition diagram for the present invention.

[0022] Figure 7 This is a flowchart of the edge computing node prediction and switching process of the present invention.

[0023] Figure 8 This is a schematic diagram of the overlapping area of ​​5G-4G network coverage according to the present invention.

[0024] Figure 9 This is a schematic diagram of the physical deployment of edge computing nodes and core network equipment in this invention.

[0025] Figure 10 This is a schematic diagram of the UE hardware security zone key storage structure of the present invention. Detailed Implementation

[0026] like Figure 9 As shown, the network architecture of this invention comprises a three-layer structure: a core network layer, an edge / access layer, and a terminal layer. In the core network layer, the left side represents the 5G domain, containing the 5G core network and its AMF (Access and Mobility Management Function Entity); the right side represents the 4G domain, containing the 4G core network and its MME (Mobility Management Entity). The two are interconnected via the N26 interface to achieve network interoperability. In the edge / access layer, gNB base stations are deployed in the 5G domain, and eNB base stations are deployed in the 4G domain. Edge computing nodes are deployed near the gNB to perform handover prediction and security context caching functions. The AMF connects to the gNB via the NG interface, and the MME connects to the eNB via the S1-MME interface. In the terminal layer, user equipment (UE) can communicate with the gNB via the NR-Uu air interface or with the eNB via the LTE-Uu air interface. The deployment location of the edge computing nodes close to the access network equipment reduces communication latency, improves the real-time performance and accuracy of handover prediction, and simultaneously reduces the load on the core network, optimizing network performance.

[0027] like Figure 10As shown, the user equipment terminal chip is internally divided into two areas: a general storage area and a hardware security area. The general storage area is a regular storage space accessible to the application layer, used to store non-sensitive information such as application data, temporary cache, configuration files, and log files. The hardware security area is an isolated storage area within the chip, separated from the general storage area by a physical isolation boundary to prevent unauthorized access at the software level.

[0028] The hardware security zone is further subdivided into three storage units based on key usage and lifecycle. The 5G key storage unit is used to permanently store the 5G core key KAMF, which is generated during the 5G network authentication phase and remains valid. The temporary key cache unit is used to temporarily store the first intermediate master key, which is only used during the handover preparation phase and is destroyed immediately after the handover to avoid the risk of key leakage. The 4G key storage unit is used to store the second master key KASME and its derived NAS encryption key, NAS integrity key, and other key materials used after the handover, such as the KeNB.

[0029] An encryption engine module is configured outside the hardware security zone, responsible for performing key derivation calculations based on the received freshness parameters. The encryption engine converts the first and second freshness parameters into a first intermediate master key and a second master key, respectively, and writes the derivation results into the corresponding storage units according to a predetermined storage strategy. When the handover process is triggered, the first intermediate master key in the temporary key cache is further processed and converted into key material in the 4G key storage unit, completing the secure transition from the 5G key system to the 4G key system. This layered and isolated storage architecture ensures the confidentiality and integrity of the keys throughout the entire handover process.

[0030] like Figure 5 As shown, the present invention differs significantly from traditional 5G to 4G handover schemes in terms of security and timeliness. In traditional handover schemes, the user equipment executes the handover operation immediately upon receiving the handover command. At this time, the security context of the 4G system has not yet been established, resulting in a data exposure window of approximately 10 milliseconds. Data transmitted during this window lacks integrity and encryption protection, making it vulnerable to eavesdropping and tampering attacks. Furthermore, since the 4G security key is only derived after the handover, if an anomaly occurs during the handover process causing key derivation failure, the system needs to re-initiate the identity authentication process. This carries the risk of retransmitting identity identifiers such as IMSI over the air interface, reducing the level of user privacy protection and increasing the probability of handover failure.

[0031] In contrast, the present invention pre-derives and synchronizes the 4G security key before the handover is executed. When the user equipment receives the handover command, it already possesses a complete 4G key system, including the NAS encryption key, the NAS integrity key, and the access layer core key KeNB. Therefore, when the user equipment actually accesses the 4G system, the security protection mechanism can be immediately activated, achieving a zero data exposure window. This pre-established security context mechanism effectively avoids key derivation failures during the handover process, eliminates the risk of identity retransmission, and significantly improves the handover success rate.

[0032] Performance comparison metrics show that the proposed solution reduces the data exposure window from approximately 10 milliseconds in traditional solutions to zero, lowering the handover failure rate by 75% while avoiding the security risks associated with exposed identities. The key establishment timing is moved from after the handover to before, and this timing optimization not only enhances the security of the handover process but also improves its reliability and efficiency, providing a more comprehensive solution for secure interoperability between 5G and 4G systems.

[0033] To further understand the content of this invention, a detailed description of the invention is provided in conjunction with the accompanying drawings and embodiments. The specific embodiments described herein are for illustrative purposes only and are not intended to limit the invention. It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0034] Specifically, this embodiment of a security management method before switching from a new generation mobile communication system to a previous generation mobile communication system may include: S101, a security management method before switching from a first-generation mobile communication system to a second-generation mobile communication system, wherein the first-generation mobile communication system is a new generation mobile communication system and the second-generation mobile communication system is the previous generation mobile communication system, characterized in that the source-side core network control plane network element generates a first intermediate master key based on the first-generation core key and a first freshness parameter through a key derivation function, wherein the first freshness parameter is only generated within the first-generation system and transmitted to the user equipment, and the second-generation system cannot obtain the first freshness parameter.

[0035] Upon receiving a handover request notification, the source-side core network control plane element generates a first freshness parameter. This first freshness parameter is a non-access stratum downlink count and is forwarded to the user equipment only through the source-side access network. The target-side core network control plane element cannot obtain this first freshness parameter. The source-side core network control plane element uses the shared first-generation core key, the generated first freshness parameter, and a handover scenario identifier as input to generate a first intermediate master key through a key derivation function. This first intermediate master key is sent to the target-side core network control plane element along with the relocation request message. Upon receiving the same first freshness parameter, the user equipment uses its locally stored first-generation core key, the first freshness parameter, and the same handover scenario identifier as input to independently generate a first intermediate master key identical to that of the source-side core network control plane element through the same key derivation function. The target-side core network control plane element only holds the first intermediate master key and cannot reverse-engineer the first freshness parameter or the first-generation core key, thus ensuring that neither the first-generation core key nor the first freshness parameter is transmitted to the second-generation mobile communication system.

[0036] For example, in a 5G to 4G handover scenario, the source-side core network control plane element, such as the AMF, generates a first freshness parameter after receiving the handover request notification. This parameter serves as a non-access stratum downlink counter to ensure key uniqueness and is forwarded to the user equipment via the source-side access network, such as the gNB. This prevents the target side, such as the MME, from obtaining this parameter, thereby maintaining the independence of the 5G security domain and helping to block potential security snooping. In one possible implementation, the source-side core network control plane element combines a shared first-generation core key, such as the KAMF, with the generated first freshness parameter to distinguish the handover scenario's identifier value. It then generates a first intermediate master key using a key derivation function, such as the KDF. This process is similar to a one-way hash function operation, where the mixed input parameters produce an irreversible output. This first intermediate master key is sent to the target-side core network control plane element along with a relocation request message. This approach enables a secure transition without exposing source-side core information, thus improving the overall handover security.

[0037] For example, after receiving the same first freshness parameter, the user equipment (UE) uses the locally stored first-generation core key, the parameter, and the same identifier value as input to generate a consistent first intermediate master key through the same key derivation function. This independent generation process ensures that the UE is synchronized with the source side without relying on the target side's intervention. This allows for early key preparation, which helps reduce the risk of data exposure during handover. In one possible implementation, the target side's core network control plane elements only hold the first intermediate master key. However, due to the unidirectional nature of the key derivation function, it is impossible to deduce the first freshness parameter or the first-generation core key in reverse. This isolation mechanism is similar to the partition protection of a firewall, ensuring that neither the first-generation core key nor the first freshness parameter is transmitted to the second-generation system. This achieves complete reverse security isolation, which is beneficial for protecting the core assets of the second mobile communication system.

[0038] For example, from another perspective, in vehicle-to-everything (V2X) applications, when a vehicle switches from 5G coverage to 4G, the first freshness parameter generated by the source side is limited to internal 5G transmission. The user equipment (UE) uses this parameter to generate the first intermediate master key. While the target side receives this key, it cannot trace the source parameter. This multi-faceted support ensures that real-time data, such as location information, is not leaked, which is beneficial for maintaining business continuity. In one possible implementation, considering industrial control scenarios, the process of the UE independently generating the first intermediate master key is synchronized with the source side. Combined with the isolated holding by the target side, a mutually supportive security chain is formed. This can prevent threats such as quantum attacks and is beneficial for protecting sensitive environments. Further, for example, in multi-key system compatibility, the isolation of the generation and transmission of the first freshness parameter, combined with the use of key derivation functions, supports the generation of the first intermediate master key from variant inputs such as KSEAF. The multi-directional support that the target side cannot reverse-engineer enhances scalability and is beneficial for a smooth transition to 6G in the future. In one possible implementation, from a privacy perspective, the source side generates parameters and forwards them to the user device. After the user device generates the key, the target side only holds the intermediate result. This logical progression avoids exposing identity identifiers such as IMSI in 4G, which is beneficial to improving user privacy. For example, in terminal adaptation scenarios, low-barrier upgrades such as firmware updates allow the user device to process the first freshness parameter to generate a consistent key. This isolation and mutual support from the target side ensures broad coverage of dual-mode terminals and helps reduce deployment costs.

[0039] In one possible implementation, by combining multiple approaches, the temporary storage and destruction of the first intermediate master key in the key lifecycle management, combined with the characteristic of being unreversely obtainable, forms a closed-loop protection, which helps reduce the risk of long-term leakage and thus supports security management before the switch from the first generation to the second generation.

[0040] In step S102, the source-side core network control plane element sends the first intermediate master key to the target-side core network control plane element. The transmission of the first intermediate master key does not carry any first-generation core key.

[0041] After generating the first intermediate master key, the source-side core network control plane element transmits it to the target-side core network control plane element via a dedicated interface channel. End-to-end encryption is used during transmission to ensure data confidentiality along the transmission path. The first intermediate master key does not contain any information related to the original core key during encapsulation. After obtaining the first intermediate master key from the dedicated interface channel, the target-side core network control plane element temporarily stores it in an encrypted memory area with a short validity period to prevent long-term data retention. Simultaneously, the integrity of the first intermediate master key is verified to ensure it has not been tampered with during transmission. After verification, the target-side core network control plane element further derives an intermediate key for secure activation based on the first intermediate master key. This derivation process is completed within the encrypted memory area, ensuring the first intermediate master key is not directly used for subsequent business processing. The target-side core network control plane element applies the derived intermediate key to the secure activation process and automatically destroys the first intermediate master key to ensure it is not reused or leaked, maintaining the security of key transmission from the source to the target side.

[0042] For example, the process of transmitting the first intermediate master key through a dedicated interface channel after the source-side core network control plane network element generates the first intermediate master key can be understood as a secure key migration mechanism. This dedicated interface channel refers to a communication path pre-set in the core network architecture specifically for key exchange. For example, in the 5G to 4G network handover scenario, the source-side AMF network element encapsulates the first intermediate master key into specific information elements and sends it to the target-side MME network element. This can bring the beneficial effect of key isolation because no first-generation core key is carried during transmission, thereby reducing the potential risk of leakage.

[0043] In one possible implementation, end-to-end encryption involves encrypting data packets using a pre-shared key, ensuring that the content cannot be decrypted even if intermediate nodes are compromised, which improves the overall network security level.

[0044] In one possible implementation, the target-side core network control plane element temporarily stores the first intermediate master key in an encrypted memory area after obtaining it from the dedicated interface channel. This is to achieve short-term data residency. For example, the MME element immediately places the key in a protected memory buffer after receiving it and sets an expiration period such as a short time window. This can prevent security risks caused by persistent storage. In detail, the integrity verification process involves calculating the hash value of the received data and comparing it with the checksum provided by the sender. If they match, it is confirmed that the data has not been tampered with. The benefit is to ensure the reliability of the key, connect the aforementioned transmission security, and further strengthen the trust chain from the source side to the target side.

[0045] For example, the step of the target-side core network control plane element further deriving an intermediate key for security activation based on the first intermediate master key after completing the verification can be regarded as a continuation of the key derivation chain.

[0046] In one possible implementation, this derivation process is performed within an encrypted memory area. For example, a new key is generated using a key derivation function combined with a freshness parameter, ensuring that the original first intermediate master key does not directly participate in subsequent activation. This provides the benefit of forward key security, meaning that even if a key is leaked at a certain stage, it will not affect the validity of subsequent keys. The beneficial effect is to enhance robustness during network switching, which, together with the aforementioned storage and verification, forms a complete key processing flow.

[0047] In one possible implementation, the target-side core network control plane element applies the derived intermediate key to the security activation process while simultaneously performing an automatic destruction operation on the first intermediate master key. This is to achieve key lifecycle management, such as erasing data traces in memory immediately after activation. This has the beneficial effect of preventing key reuse or leakage, maintaining the overall security framework for key transmission from the source to the target side. The beneficial effects are optimized resource utilization and reduced attack surface. This, combined with the aforementioned derivation steps, ensures seamless security throughout the migration process.

[0048] The first intermediate master key can be transmitted between the source-side AMF and the target-side MME via the N26 interface. The transmission process is protected by secure channel encryption based on TLS 1.3 to ensure that the key is not eavesdropped or tampered with during transmission.

[0049] The first intermediate master key is a temporary key, and its lifespan is strictly limited to the handover process. Specifically: it is generated at time T1 (before the handover command is issued); it is destroyed immediately at time T4 (after the user equipment successfully accesses the 4G network and completes security activation); the destruction method is: multiple random data overwrites (at least 3 times) are performed on the address where the key is located in memory, and then the memory is released to ensure that the key cannot be restored by memory recovery methods.

[0050] In step S103, the target-side core network control plane element generates a second master key based on the received first intermediate master key and second freshness parameter through the same key derivation function. The second freshness parameter is generated by the target-side core network control plane element and is only transmitted to the user equipment. The first-generation system cannot obtain the second freshness parameter.

[0051] The target-side core network control plane element obtains the first intermediate master key from the source-side core network and simultaneously generates a second freshness parameter. This second freshness parameter is independently generated by the target-side core network control plane element and is used only for transmission with the user equipment, ensuring that the first-generation network cannot obtain this parameter. After generation, it is temporarily stored in a secure area, ready for subsequent key derivation. The target-side core network control plane element transmits the second freshness parameter to the user equipment through a secure channel. Simultaneously, based on a pre-established key derivation function, it combines the first intermediate master key with the second freshness parameter to calculate initial key data. This initial key data serves as the basis for subsequent processing and is stored in a temporary buffer for further processing. The target-side core network control plane element verifies the initial key data. After confirming its integrity, it calls the key derivation function again to perform a second derivation of the initial key data, generating the final second master key. This second master key is used only for the security protection of the current session, ensuring key isolation and freshness. The target-side core network control plane element synchronizes the second master key with the user equipment to ensure that both parties hold the same key data. At the same time, it restricts the transmission range of the second master key, using it only between the target-side core network control plane element and the user equipment, thus completing the generation and distribution process of the second master key.

[0052] The second freshness parameter can be dynamically generated by the core network control plane element on the target side after receiving the handover request. Its content is selected according to the network deployment strategy as follows: (1) Second generation non-access stratum uplink counter: take the latest NAS uplink counter value of the user equipment in the 4G system. The value increases with each uplink message to ensure uniqueness and timeliness; (2) Partial static identifier of user equipment: take the last 4 digits of the International Mobile Subscriber Identity (IMSI) code, which is applicable to fallback scenarios or counter unavailability.

[0053] To avoid parameter conflicts during concurrent handover by multiple users, the target network element maintains an independent counting sequence for each UE and checks its uniqueness before generating parameters. If a duplicate is detected, the count value is automatically incremented until it becomes unique.

[0054] In one possible implementation, the process of the target-side core network control plane element obtaining the first intermediate master key from the source-side core network involves secure interface transmission, such as key migration via the N26 interface. This migration ensures continuity during the handover from 5G to 4G. Meanwhile, the generation of the second freshness parameter can be achieved by using a random number generator to produce a unique value. This value is limited to use between the target-side core network control plane element and the user equipment, thereby preventing the intervention of first-generation networks such as 4G systems and avoiding potential replay attack risks. This approach can improve the isolation of the overall key system and is beneficial for maintaining the security boundary during the handover process.

[0055] For example, the generation and temporary storage of the second freshness parameter within a secure area is similar to using a hardware security module to store sensitive data. For instance, in actual deployment, a target-side core network control plane element, such as an MME entity, generates a parameter value based on a timestamp and a random seed and places it in an isolated memory area. This storage method prevents the parameter from being accessed by external network elements and is beneficial to the reliability of subsequent key derivation because it ensures the freshness and immutability of the parameter, supporting the independence of key generation from multiple directions.

[0056] In one possible implementation, the second freshness parameter can be transmitted to the user equipment via a secure channel using an encrypted NAS signaling channel, for example, by embedding the parameter in the handover signaling to ensure that the transmission is protected from eavesdropping. At the same time, based on a pre-established key derivation function such as the SHA-256 hash function, the first intermediate master key is combined with the second freshness parameter to calculate the initial key data. This calculation process involves concatenating the two inputs and performing a hash operation to obtain a fixed-length output as the initial key data, which is stored in a temporary buffer. This combination method is beneficial to enhance the diversity of keys and reduce the security weaknesses caused by dependence on a single parameter. It mutually supports the improvement of key freshness from the perspective of isolated transmission and computational fusion.

[0057] For example, after verifying the integrity of the initial key data, the key derivation function is called again to generate a second master key. For example, the verification can be achieved by comparing hash checksums. If they match, the initial key data is input into the function for further derivation operations. This secondary derivation process is similar to chained key generation, ensuring that the second master key is only used in the current session. This limits the exposure time of the key and helps reduce the risk of leakage. The logical chain of checksum derivation forms an enhancement of security protection.

[0058] In one possible implementation, synchronizing the second master key with the user equipment can be achieved through a secure activation message, such as synchronizing key data in a 4G security mode command, ensuring that both parties hold the same value, while limiting the transmission range to only between the target-side core network control plane network element and the user equipment. This restriction helps prevent the key from spreading to unrelated networks, effectively completing the generation and distribution process, and supporting the realization of key isolation and freshness from multiple directions of synchronization and range control.

[0059] For example, in actual network handover scenarios, such as the migration from 5G AMF to 4G MME, the first intermediate master key is obtained from the source side and combined with the locally generated second freshness parameter to derive the second master key. This process avoids the risk of parameter mixing during transmission and is beneficial to resisting tampering attacks. At the same time, the user equipment side also independently calculates the same key to ensure seamless handover. In this way, the complete chain from generation, transmission, derivation to synchronization supports each other, improving the overall security strength and compatibility of the solution.

[0060] In step S104, before actually switching to the second-generation system, the user equipment receives the first freshness parameter and derives the first intermediate master key based on the first-generation core key. Then, after receiving the second freshness parameter, it derives the second master key based on the first intermediate master key, so that the user equipment has a complete second-generation security key system when accessing the second-generation system.

[0061] After registering in a 5G mobile communication network, the User Equipment (UE) receives a downlink non-access stratum (NASS) message containing a first freshness parameter from the Access and Mobility Management (AM) entity. This first freshness parameter is the NASS downlink counter value. The UE performs a key derivation function operation based on the 5G core root key, the first freshness parameter, and a preset function code to obtain a first intermediate master key. When the AM sends an interface message to the Mobility Management (MML) entity, it also sends the same first freshness parameter. Upon receiving this message, the MML, based on the 4G seed key mapped from the 5G core root key, the first freshness parameter, and the same function code, derives a first intermediate master key identical to that of the UE. The MML sends a second freshness parameter to the UE in a handover command message. Upon receiving this parameter, the UE immediately uses the first intermediate master key as the input key and performs a key derivation function operation based on the second freshness parameter to obtain a second master key. The UE, carrying the fully derived second master key, directly accesses the 4G base station. The base station activates the 4G security context based on the second master key synchronously transmitted by the MML entity. The UE possesses a complete 4G security key system the instant it accesses the 4G network.

[0062] For example, in a fifth-generation mobile communication network, after a user equipment completes registration, it obtains downlink non-access stratum messages from the access and mobility management function entity. These messages carry a first freshness parameter as the downlink counter value of the non-access stratum. The user equipment uses the fifth-generation core root key in combination with this parameter and a preset function code to perform key derivation function operations to generate a first intermediate master key. This operation ensures the uniqueness and freshness of the key, which helps prevent replay attacks and improves security during the handover process.

[0063] In one possible implementation, the access and mobility management entities send the same first freshness parameter to the mobility management entity via interface messages. The latter performs a similar operation based on the fourth-generation seed key mapped from the fifth-generation core root key, the parameter, and the same function code to obtain a first intermediate master key matching the user equipment. This synchronization mechanism ensures key consistency between the two parties, facilitating seamless handover and preventing access failures due to key mismatches. For example, the mobility management entity sends a second freshness parameter in the handover command message. Upon receiving this parameter, the user equipment uses the first intermediate master key as a basis and performs another key derivation function operation to generate a second master key. This hierarchical derivation method enhances key isolation, helps maintain independent security contexts across different network domains, and reduces potential leakage risks. In another possible implementation, the user equipment directly accesses the fourth-generation base station using the generated second master key, while the base station relies on the same second master key transmitted by the mobility management entity to activate the fourth-generation security context. This immediate availability ensures that the user equipment has a complete security key system when accessing the fourth-generation network, benefiting service continuity and privacy protection, and avoiding interruptions or identity exposure in traditional methods. For example, consider a real-world scenario where a user equipment (UE) triggers a handover when moving through a high-load area of ​​a 5G network. First, a first freshness parameter is obtained via downlink messages, and a first intermediate master key is derived. This step helps bridge the security domains of the two networks. Subsequently, parameter synchronization between entities ensures consistency, facilitating reliable transmission. Next, the issuance and derivation of the second parameter completes the key system construction, enabling rapid response. Finally, the complete key system is activated upon access, facilitating zero-delay service recovery. These steps support each other, forming an efficient handover chain. In one possible implementation, from another perspective, if the UE handover occurs in an edge coverage area, the introduction of the first freshness parameter prevents the reuse of old keys, improving security; the accompanying sending of interface messages enables cross-entity coordination, improving network compatibility; the processing of the second freshness parameter strengthens layered protection, improving risk isolation; and direct use during the access phase ensures immediate security, improving user experience. These aspects collectively support a smooth transition. For example, in a multi-carrier environment, this process allows access and mobility management entities to flexibly map seed keys, which is beneficial for interoperability; the standardized application of derivation functions ensures compatibility and facilitates deployment; step-by-step key generation reduces long-term storage requirements and helps prevent leakage; and the integrity of the final system supports diverse terminal scenarios and facilitates wide coverage. These interconnected benefits enhance the overall robustness of the solution.

[0064] S2, after the handover requirement is triggered, the source-side core network control plane element generates the first freshness parameter. The first freshness parameter includes the first-generation NAS downlink count or the first-generation side random number, which is sent to the user equipment through the first-generation access network. The target-side core network control plane element and the second-generation access network cannot parse the actual value of the first freshness parameter.

[0065] Upon receiving a handover request, the source-side core network control plane element generates a first freshness parameter. This parameter is incremented by a first-generation non-access stratum downlink counter maintained internally by the source-side core network control plane element and encapsulated in a dedicated non-access stratum container. This container is transparently forwarded to the user equipment (UE) via the first-generation access network. The dedicated non-access stratum container uses a pre-established integrity protection key between the first-generation core network control plane element and the UE for integrity protection. The target-side core network control plane element and the second-generation access network only perform forwarding operations and cannot parse the actual value of the first freshness parameter within the container. After receiving the integrity-protected first freshness parameter, the UE uses the integrity protection key shared with the source-side core network control plane element to verify the container's integrity and extract the first freshness parameter. This parameter is then used to jointly derive the intermediate key with the source-side core network control plane element. In subsequent processes, the target-side core network control plane element only receives the hash value of the intermediate key derived from the first freshness parameter, returned by the UE. It cannot reverse-engineer the first freshness parameter itself, ensuring that the first freshness parameter is always transmitted only between the source-side core network control plane element and the UE.

[0066] In one embodiment, when the source-side core network control plane element generates the first freshness parameter, it directly retrieves the current value from the internally maintained first-generation non-access stratum downlink counter and increments it by 1 to obtain the parameter. This parameter is then placed into a non-access stratum security container specifically agreed upon by the source-side core network control plane element and the user equipment. This container is located within a dedicated information element of the handover command message. The first-generation access network only acts as a transparent pipe for forwarding and does not parse the container content at all, thus keeping the actual value of the first freshness parameter invisible to the first-generation access network. For example, if the current counter value of the source-side core network control plane element is 1000, after generating the first freshness parameter, the counter becomes 1001. This parameter 1000 is placed in the non-access stratum security container and subjected to integrity protection. When forwarding the handover command, the first-generation access network only reads the routing information outside the container; the first freshness parameter inside the container remains unknown to the first-generation access network.

[0067] Specifically, the non-access stratum security container uses an integrity protection key shared by the source-side core network control plane element and the user equipment to calculate the message authentication code. When the target-side core network control plane element receives the uplink handover confirmation message from the user equipment, it can only see the external identifier of the container and cannot decrypt the integrity protection, thus failing to obtain the true value of the first freshness parameter. The second-generation access network does not even come into contact with this container throughout the entire process, further ensuring that the first freshness parameter only circulates between the source-side core network control plane element and the user equipment. In one possible implementation, after receiving the handover command, the user equipment first verifies the integrity of the non-access stratum security container using the same integrity protection key as the source-side core network control plane element. Only after successful verification does it extract the first freshness parameter, which is then used to jointly execute a key derivation function with the source-side core network control plane element to generate an intermediate key. This intermediate key is subsequently used by the user equipment to derive the target-side key, but when the user equipment reports to the target-side core network control plane element, it only sends the one-way function value of the intermediate key, ensuring that the target-side core network control plane element can only verify consistency and cannot reverse-engineer the first freshness parameter. For example, after the user equipment extracts the first freshness parameter 1000, it inputs it together with the pre-shared root key of the source core network control plane element into the key derivation function to obtain the intermediate key. Then, it calculates the hash value of the intermediate key and sends it up. The target core network control plane element can only compare the correctness of the hash value and cannot deduce the original first freshness parameter from the hash value. This achieves strict isolation of the first freshness parameter from the target core network control plane element and the second-generation access network on the transmission path, significantly improving parameter confidentiality and effectively preventing replay attacks.

[0068] S3, the target-side core network control plane element generates the second freshness parameter. The second freshness parameter includes the uplink count of the second-generation NAS or a partial static identifier of the user equipment. It is transparently transmitted to the user equipment through the source-side core network control plane element and the first-generation access network. The source-side core network control plane element only performs transparent transmission and does not parse the actual value of the second freshness parameter.

[0069] When the target-side core network control plane element receives a handover request, it generates a second freshness parameter. This parameter contains a second-generation non-access stratum uplink count or a partial static identifier of the user equipment, ensuring the parameter's uniqueness and dynamism. After generation, it is encapsulated into a dedicated information unit, ready for subsequent transmission. The encapsulated second freshness parameter is forwarded through the source-side core network control plane element. The source-side core network control plane element only performs a transparent transmission operation and does not parse or modify the content of the second freshness parameter, ensuring the parameter's integrity during transmission. After being transparently transmitted by the source-side core network control plane element, the second freshness parameter is further forwarded to the user equipment through the first-generation access network. The first-generation access network also only performs a forwarding function and does not process the parameter content, ensuring the isolation of the parameter transmission path. After receiving the second freshness parameter, the user equipment performs subsequent key update operations based on this parameter, ensuring that the key freshness is maintained during the handover process, completing the complete transmission of the second freshness parameter from the target-side core network control plane element to the user equipment.

[0070] For example, in one possible implementation, when the target-side core network control plane element, such as the Access and Mobility Management Function (AMS) entity, receives a handover request signal from the source side, it triggers the generation process of a second freshness parameter. This parameter can specifically adopt a second-generation non-access stratum uplink counting form, i.e., an incremental value based on the user equipment's communication history, or a portion of the user equipment's static identifier, such as the last few digits of the International Mobile Subscriber Identity (IMSI), to ensure its uniqueness and dynamism. This prevents parameter reuse, thereby improving overall security. Subsequently, the generated parameter is encapsulated into a dedicated information unit, for example, using a type-length value format for structured packaging, facilitating efficient transmission in the network. This encapsulation method maintains the integrity and compatibility of the parameter, laying the foundation for subsequent forwarding.

[0071] In one possible implementation, the encapsulated second freshness parameter is sent to a source-side core network control plane element, such as a mobility management entity. This element only performs a transparent transmission operation, that is, it directly forwards the parameter without parsing or modifying its content. For example, in a real network environment, the source-side element does not attempt to interpret its internal count or identifier value after receiving the parameter; it only acts as a data packet relay. The beneficial effect of this is to avoid potential interference from the source side to the target-side parameters, ensuring isolation and security during transmission. In another possible implementation, the second freshness parameter, after being transparently transmitted from the source side, continues to be forwarded through a first-generation access network, such as an evolved Node base station. This access network is also limited to forwarding functions. For example, in a 4G to 5G handover scenario, the access network equipment only transmits the parameter as an opaque data block to the user equipment without processing its content. The beneficial effect of this method is to strengthen the isolation of the parameter transmission path, reduce the risk of tampering by intermediate nodes, and thus maintain the network trust chain. In one possible implementation, after receiving the second freshness parameter, the user device, such as a smartphone, performs a key update operation based on this parameter. For example, it calculates a new key by combining a local counter with the received parameter. This not only maintains key freshness during the handover process but also has the beneficial effect of resisting replay attacks through dynamic parameters, ensuring the secure continuity of the communication session. For example, from another perspective, in a commercial 5G to 4G fallback scenario, when the target network element generates parameters, it can preferentially select some static identifiers of the user device as content to adapt to the compatibility requirements of different network standards. The benefit of this selection is that it enhances the cross-system applicability of the parameters. At the same time, through strict transparent transmission between the source and access networks during transmission, end-to-end isolation of the parameters from generation to reception is achieved. The mutually supporting direction is that if the parameters are tampered with, the key update at the device end will fail, thereby timely detecting attacks and further strengthening the system robustness. In one possible implementation, considering the scenario of concurrent switching among multiple users, the target-side network element ensures the uniqueness of each user identifier when generating parameters. For example, it assigns independent counting sequences to different devices. This has the beneficial effect of avoiding parameter conflicts and improving reliability under large-scale deployment. Meanwhile, the pass-through mechanism ensures that the parameters are not parsed by intermediate nodes such as the source-side network element, supporting the goal of privacy protection. Finally, the parameter transmission is completed to support seamless key management.

[0072] S4, the key derivation function is the KDF function defined by the 3GPP standard, and different function codes are used to distinguish the derivation scenarios when generating the first intermediate master key and the second master key.

[0073] In the transition from 5G to 4G mobile communication networks, after obtaining the first freshness parameter from the 5G core key and the 5G network identifier, a first intermediate master key is generated by using the key derivation function defined by the 3G Partnership Program standard and inputting a preset first function code. The first intermediate master key is then combined with the 4G network identifier to obtain a second freshness parameter different from the first freshness parameter, which is then input into the key derivation function defined by the 3G Partnership Program standard. Simultaneously, the function code is replaced with a preset second function code to generate a second master key. After the 4G Mobility Management Entity (SMMI) completes security activation, the second master key triggers the immediate destruction of the first intermediate master key, retaining only the second master key and its derived subkeys for subsequent 4G security domain protection. When the 4G network supports higher identifier integrity and encryption algorithms, the corresponding subkeys are directly re-derived based on the second master key by modifying the algorithm identifier parameter in the key derivation function, achieving algorithm switching under different function code distinctions.

[0074] In this invention, the key derivation function can be the KDF (Key Derivation Function) function defined in the 3GPP TS 33.501 standard, specifically the KDF is implemented based on HMAC-SHA-256.

[0075] When generating the first intermediate master key, the input parameters include: root key: KAMF (5G core key); freshness parameter: first freshness parameter N1 (such as NAS downlink counter value); function code: fixed value 0x01 (used to identify the "5G→4G handover intermediate key generation" scenario); network identifier: 5G network identifier (such as SN name).

[0076] The calculation formula is as follows: K_intermediate = KDF(K_AMF, "5G_to_4G_Intermediate_Key" || N_1 || SN_name) In this context, "||" represents byte concatenation, and the string "5G_to_4G_Intermediate_Key" corresponds to the semantic identifier of function code 0x01.

[0077] When generating the second master key, the input parameters include: Root key: K_intermediate (first intermediate master key); Freshness parameter: Second freshness parameter N2 (such as 4G NAS uplink counter value or the last 4 digits of IMSI); Function code: Fixed value 0x02 (used to identify the "4G master key generation" scenario); Network identifier: 4G network identifier (such as eNodeB ID).

[0078] The calculation formula is as follows: K_eNB = KDF(K_intermediate, "4G_Master_Key" || N_2 || eNodeB_ID) The resulting K_eNB is the second master key, used to derive the NAS encryption key, NAS integrity key, and KeNB for the 4G system.

[0079] like Figure 6 The diagram illustrates the lifecycle changes of each key during the handover process. Throughout the handover, the 5G core key KAMF remains valid and is used for key derivation. The first intermediate master key undergoes a complete lifecycle: it is generated at time T1, with its initial state represented by a hollow circle; at time T2, it is transmitted to the target-side MME via a secure channel and temporarily stored in the encrypted memory area; at time T3, it is used to derive the second master key KASME; and at time T4, when the handover is complete, it is destroyed, marked with a red cross and highlighted with a dashed box. The second master key KASME is generated at time T3, securely activated and becomes valid at time T4 (represented by a solid circle), and continues to be used at time T5 to support subsequent secure communication. Derived keys are derived from KASME at time T4, with the derivation relationship indicated by dashed arrows, and are also retained for use at time T5. This state transition diagram clearly shows the key states of key generation, transmission, derivation, activation, destruction, and retention, ensuring security and standardized key management during the handover process. It also enables the temporary use and timely destruction of the first intermediate master key, avoiding the security risks associated with long-term key storage.

[0080] In one embodiment, the process of obtaining the first freshness parameter from the fifth-generation core key and the fifth-generation network identifier involves ensuring the uniqueness of the key in handover scenarios. This enhances security isolation because the freshness parameter, based on a network-specific counter, avoids repeatedly deriving the same key, thereby reducing the potential risk of replay attacks. Specifically, when a user equipment migrates from a fifth-generation network, this parameter preferentially uses a non-access stratum downlink count value. This helps maintain the timeliness of the key and prevents the old key from being maliciously exploited, thus providing higher resistance to cracking. In one embodiment, the design of combining the first intermediate master key with the fourth-generation network identifier and introducing a second freshness parameter makes the derivation link layered and independent. This approach achieves hierarchical isolation of keys, ensuring that even if the first-layer key is exposed, it will not affect the security of subsequent layers, thus providing stronger protection. For example, in actual deployment, if an attacker intercepts the first freshness parameter, the difference between this parameter and the second parameter ensures the independent generation of the second master key, thereby supporting seamless handover without sacrificing security. In one embodiment, the mechanism that triggers the destruction of the first intermediate master key upon activation of the second master key emphasizes the short lifespan of the key. This significantly reduces the leakage window because retaining only the necessary keys reduces storage risk and optimizes resource utilization, thereby improving overall system efficiency. Specifically, immediate destruction after verification by the fourth-generation mobility management entity prevents the risks associated with long-term holding of transitional keys. For example, in high-load networks, this immediate cleanup helps maintain performance stability and strengthens resistance to new threats. In another embodiment, modifying the algorithm identifier parameters in the key derivation function when upgrading the network algorithm allows for flexible adaptation to new standards. This allows for the integration of higher identifier integrity and encryption without rebuilding the entire key structure, resulting in improved compatibility and scalability. For example, when introducing a new algorithm in a fourth-generation network, subkeys can be derived directly by adjusting parameters based on the second master key. This ensures smooth switching between different function codes, avoids complex reconstruction, and maintains security continuity.

[0081] It's important to note that the aforementioned steps, from obtaining the freshness parameter to generating the first intermediate master key, lay the foundation for subsequent integration with network identifiers and replacement function codes. This is because the first key acts as a bridge, directly inputting into the derivation of the second key. This connectivity enhances the continuity and security of the derivation, achieving complete decoupling during handover. For example, without different freshness parameters, the derivation might introduce associated vulnerabilities, but this chained design effectively isolates the 5G and 4G domains, providing more reliable protection. Furthermore, the design of retaining the second master key after destroying the first intermediate master key is integrated with algorithm switching parameter modifications. Destruction reduces unnecessary key exposure, while re-derivation based on the retained key ensures uninterrupted service during upgrades, thus optimizing the overall key management process and improving adaptability. For instance, in real-world scenarios, this integration allows network operators to respond quickly to algorithm updates without impacting user experience, thereby strengthening defenses against threats such as quantum computing. It should be noted that the entire process, from initial parameter acquisition to final algorithm switching, forms a closed-loop logic. The output of each stage serves to enhance the security of the next stage, which helps to maintain consistent high-strength protection in multi-network environments, thereby bringing comprehensive technical benefits.

[0082] S21, both the first intermediate master key and the second master key are 256 bits in length. The target-side core network control plane network element further derives the second-generation NAS layer encryption key, the NAS layer integrity key and the access layer core key KeNB based on the second master key.

[0083] The target-side core network control plane element obtains the first intermediate master key from the source-side core network. This first intermediate master key is 256 bits long and is generated by the source side based on the source security domain root key through a key derivation function combined with the first function code and the source network identifier. Using the first intermediate master key as input, the target-side core network control plane element generates a second master key through a key derivation function combined with the second function code and the target network freshness parameter. This second master key also maintains a 256-bit length and is independent of the source security domain. Using the second master key as the root key, the target-side core network control plane element generates a second-generation non-access stratum encryption key and a second-generation non-access stratum integrity key through a key derivation function, and simultaneously generates an access stratum core key. The target-side core network control plane element distributes the access stratum core key to the target base station, which then uses this access stratum core key to further derive user plane encryption keys and radio resource control signaling keys, thereby completing the establishment of the second-generation complete key system.

[0084] In one possible implementation, the target-side core network control plane element obtains a first intermediate master key from the source-side core network. This key is generated by the source side using the source security domain root key and a key derivation function to fuse a first function code and the source network identifier, ensuring a secure transition during the key bridging process and preventing direct exposure of source domain information, thereby improving the overall handover security. In one embodiment, based on this first intermediate master key, the target-side core network control plane element uses a key derivation function to integrate a second function code and the target network freshness parameter to generate a second master key. This step maintains consistent key length and strengthens the independence of the target domain, which helps to block potential reverse tracing risks and improves the robustness of the key system. Specifically, using the second master key as the root key, the target-side core network control plane element derives a second-generation non-access stratum encryption key and a second-generation non-access stratum integrity key respectively through a key derivation function, while simultaneously generating an access stratum core key. This process ensures that the protection mechanisms of the non-access stratum and the access stratum are activated synchronously, which helps to achieve seamless secure context transfer and reduce handover interruption time. In one possible implementation, the target-side core network control plane element distributes the access layer core key to the target base station. The base station then uses this key to further derive user plane encryption keys and radio resource control signaling keys. This distribution and derivation mechanism completes the construction of the entire key system, enhancing data and signaling protection on the base station side, optimizing user experience, and reducing eavesdropping threats. For example, in actual deployment, obtaining the first intermediate master key is similar to transmitting it from the 5G source-side AMF to the 4G target-side MME, ensuring that key bridging during handover does not rely on additional authentication, saving resources and accelerating the process. This method is linked to the generation of the second master key, as the latter directly utilizes the former's input to achieve key hierarchy isolation, which is beneficial for maintaining high security in multi-network coexistence environments. Specifically, the derivation process of the second master key can be viewed as a secondary transformation of the first intermediate master key, incorporating target freshness parameters to refresh the key state and avoid reuse risks. This refresh is closely related to subsequent non-access layer key generation, ensuring that NAS layer signaling is protected in the target domain in real time, which is beneficial for preventing man-in-the-middle attacks. In one embodiment, the generation of non-access stratum encryption keys and integrity keys employs a unified derivation function, but parameters are adjusted to meet different protection requirements. For example, encryption focuses on data confidentiality while integrity emphasizes tamper resistance. This adjustment helps balance computational overhead and security strength and directly supports the parallel derivation of access stratum core keys. For instance, the distribution of access stratum core keys is similar to the MME transmitting KeNB to the eNodeB. The base station then derives user plane keys for data stream encryption. This derivation process continues the key foundation of the core network, facilitating unified management of multi-layered protection and reducing configuration complexity.

[0085] Specifically, in switching scenarios, the establishment of a complete key system can start with bridging keys and gradually expand to hierarchical derivation to ensure that each link supports each other, forming a closed-loop security framework, which is beneficial to improving network resilience and supporting future expansion.

[0086] like Figure 2 As shown, the key derivation chain demonstrates the complete derivation process from the 5G core key to the 4G master key. This derivation process uses the KDF (Key Derivation Function) defined by the 3GPP standard to ensure the one-way irreversible nature of the key.

[0087] Specifically, key derivation is divided into two stages. In the first stage, the 5G core key (KAMF / KSEAF) is used as input, combined with a first freshness parameter (such as NAS downlink count or 5G random number) and a first function code, to generate a first intermediate master key through KDF operation. This key is 256 bits long. In the second stage, the first intermediate master key is used as input, combined with a second freshness parameter (such as NAS uplink count or UE partial identifier) ​​and a second function code, to generate a second master key KASME through KDF operation. This key is also 256 bits long.

[0088] Three types of keys are derived from the second master key KASME: the NAS encryption key for encryption protection of non-access stratum signaling, the NAS integrity key for integrity protection of non-access stratum signaling, and the KeNB (access stratum core key) for establishing access stratum security contexts. The entire derivation process utilizes one-way hashing to ensure that the target 4G system cannot reverse-engineer the source 5G system's core key, thereby achieving key isolation and security assurance during cross-system handover.

[0089] S22, after receiving the first freshness parameter and the second freshness parameter, the user equipment completes the derivation of the first intermediate master key and the second master key while still maintaining the connection with the first generation access network, and immediately returns a key synchronization confirmation signaling to the first generation access network after the handover command is issued.

[0090] After receiving the first and second freshness parameters, the User Equipment (UE) performs preliminary parsing of these parameters. While maintaining connection with the first-generation access network (1G network), it derives the first intermediate master key based on pre-established key derivation logic, generating first intermediate master key data. Based on the first intermediate master key data, the UE continues to use the second freshness parameter, combined with preset key derivation rules, to derive the second master key while maintaining connection with the 1G network, generating second master key data. After generating the second master key data, the UE stores the first intermediate master key data and the second master key data in a hardware secure area. Upon receiving a handover command, the UE immediately returns a key synchronization confirmation signaling to the 1G network to ensure key synchronization during the handover process. When returning the key synchronization confirmation signaling, the UE encrypts the signaling content and uses the second master key data to perform integrity verification on the signaling, ensuring the security of the key synchronization confirmation signaling during transmission and completing the response to the handover command.

[0091] In one possible implementation, after receiving the first freshness parameter and the second freshness parameter, the user equipment performs preliminary parsing of these parameters to ensure data freshness, thereby avoiding key replay attacks. This parsing process involves checking the uniqueness and timeliness of the parameters, which helps to improve the overall security of key derivation.

[0092] For example, in a 5G to 4G handover scenario, the user equipment first verifies whether the first freshness parameter matches the current session. This prevents the old parameter from being maliciously exploited, improving the reliability of key synchronization. It should be noted that the derivation of the first intermediate master key is based on pre-established key derivation logic, generating the first intermediate master key data. Here, key derivation logic refers to the process of using standard functions such as SHA-256 to process input parameters. Specifically, the existing 5G master key combined with the first freshness parameter is input into the function, outputting a 256-bit key data. This method is beneficial for strengthening key strength because it transforms the parameters into an irreversible key form, reducing the risk of leakage. In one possible implementation, the second master key is further derived based on the first intermediate master key data using a second freshness parameter, generating the second master key data. This derivation rule is a pre-defined standardized rule. For example, the first intermediate master key data can be used as input, combined with the second freshness parameter, and processed through another key derivation function to output the final second master key data. This ensures the continuity of the key link, facilitates rapid key generation during connection maintenance, and avoids security vulnerabilities caused by handover delays. It should be noted that the first intermediate master key data and the second master key data are stored in the hardware secure area, and a key synchronization confirmation signal is returned immediately after receiving the switching command. Here, the hardware secure area refers to the isolated storage area in the terminal chip, which is used to protect the key from software access.

[0093] Specifically, the storage process involves encrypting the data and writing it into the storage area. This storage method is beneficial in preventing side-channel attacks because it isolates the key from the application layer, thereby improving the security level on the terminal side.

[0094] In one possible implementation, when returning the key synchronization confirmation signaling, the signaling content is encrypted and protected, and the integrity of the signaling is verified using the second master key data. Here, the encryption protection process involves using a subkey generated from the second master key data to encrypt the signaling payload, and the integrity verification involves calculating the message authentication code and appending it to the signaling.

[0095] For example, after the handover command is issued, the user equipment immediately generates an acknowledgment signal and applies verification. This ensures transmission security and helps eliminate data exposure windows because it ensures the confidentiality and integrity of the signal during air interface transmission, supporting a seamless handover experience.

[0096] It should be noted that this key synchronization confirmation mechanism supports the switching process from multiple perspectives.

[0097] For example, from a timing optimization perspective, it pre-activates the key, reducing the risk of exposure at the 10ms level; from a compatibility perspective, it requires no hardware modification and can be implemented only through software upgrades, which helps reduce deployment costs; from a privacy protection perspective, it avoids the retransmission of identity identifiers, enhancing user data privacy. These aspects support each other, forming a complete handover security framework, which is beneficial to improving overall network reliability and user satisfaction.

[0098] S23, After the handover is completed, the source-side core network control plane elements, the target-side core network control plane elements, and the user equipment all destroy the first intermediate master key, and only retain the second master key and its derived keys.

[0099] After the handover is complete, the source-side core network control plane element first marks the stored first intermediate master key as temporarily invalid and initiates a preset timer mechanism to prepare for subsequent destruction operations. This timer mechanism ensures the key will not be retrieved again. Once triggered, the source-side core network control plane element completely removes the temporarily invalidated first intermediate master key from storage and simultaneously sends a confirmation message to the target-side core network control plane element, notifying it to perform the same deletion operation synchronously. Upon receiving the confirmation message, the target-side core network control plane element also deletes the stored first intermediate master key and sends an instruction to the user equipment, requesting it to delete the key synchronously, ensuring that none of the three parties retains the first intermediate master key. After the deletion operation is complete, the source-side core network control plane element, the target-side core network control plane element, and the user equipment retain only the second master key and its derived keys for subsequent secure communication and service processing, ensuring the integrity of key management after the handover.

[0100] In one possible implementation, the process by which the source-side core network control plane element marks the first intermediate master key as temporarily invalid after the handover involves setting the access permissions associated with the key to read-only or prohibiting access. This can prevent the key from being used accidentally before it is destroyed, thereby maintaining temporary isolation of key management.

[0101] For example, this marking is achieved by updating the key metadata field, such as adding an expiration tag to the storage database. The tag contains a timestamp to record the marking time, which is beneficial for subsequent auditing and synchronization operations and avoids the risk of key misuse during the transition period.

[0102] It should be noted that starting the preset timer mechanism means initializing an internal timer that runs synchronously based on the network clock. The trigger condition is that the next step of clearing is automatically executed after the preset time is reached. This mechanism helps to ensure the automation and consistency of the destruction operation and reduce errors that may be introduced by manual intervention.

[0103] In one possible implementation, the specific method for the source-side core network control plane element to clear the first intermediate master key after the preset timer mechanism is triggered includes calling the deletion function of the storage interface to erase the key data from memory and persistent storage, while generating a log to record the clearing event. This helps to track the entire key lifecycle and send a clearing confirmation message to the target-side core network control plane element. This message is transmitted through an encrypted signaling channel and contains a verification token to confirm the sender's identity, which helps to prevent synchronization failure caused by forged messages.

[0104] For example, the structure of the clearing confirmation message includes a header field to identify the message type and a payload carrying a key identifier, so that the target core network control plane element can accurately match and perform the corresponding operation after receiving it, further enhancing the security of multi-party coordination.

[0105] It should be noted that the clearing operation of the target-side core network control plane element after receiving the clearing confirmation message is similar to the process on the source side. After verifying the integrity of the message, it calls the local deletion routine to remove the key. This consistent clearing method is beneficial to maintaining system symmetry and sends a clearing instruction to the user equipment. This instruction is encapsulated in a dedicated NAS message and contains a digital signature to ensure non-repudiation, so that the user equipment can respond securely.

[0106] For example, when the user equipment receives the instruction and performs the clearing operation, it will erase the key buffer in the security module and return an acknowledgment response to the target core network control plane network element. This closed-loop feedback is beneficial to verify that the three parties complete the destruction synchronously and avoid potential vulnerabilities of residual keys.

[0107] In one possible implementation, the process of retaining the second master key and its derivative keys after the cleanup operation involves migrating these keys to an active security context for subsequent session encryption and integrity protection. This retention mechanism is beneficial for seamlessly continuing business continuity without introducing additional overhead, while further enhancing resistance to attacks by periodically rotating the derivative keys.

[0108] It should be noted that the entire process, from marking to retention, forms an ordered chain, in which the marking state serves as a prerequisite for clearing, message passing acts as a synchronization bridge, and ultimately achieves an optimized configuration that retains only the necessary keys, which is beneficial for minimizing storage consumption and leakage exposure.

[0109] S31, the first freshness parameter is encapsulated in TLV format, and the tag value is a value dedicated to the first generation. After the target-side core network control plane network element and the second-generation access network identify the tag, they directly discard or pass through it and cannot obtain the actual content of the parameter.

[0110] After the source-side core network control plane element generates the first freshness parameter, it is encapsulated using a type-length value format, with a tag value set to a preset value specifically for identifying the first-generation network. The encapsulated first freshness parameter is transmitted to the target-side core network control plane element via a dedicated signaling field on the interface. The target-side core network control plane element recognizes the tag value and directly transmits the encapsulated parameter. The target-side core network control plane element then forwards the transmitted encapsulated parameter to the second-generation access network. The second-generation access network recognizes the tag value and discards the encapsulated parameter, unable to parse the content of the first freshness parameter. In subsequent key derivation, the second-generation access network only uses the second freshness parameter, which it can parse. The first freshness parameter, isolated by its tag value, cannot be obtained by the second-generation access network.

[0111] For example, after the source-side core network control plane network element, such as the access and mobility management function, generates the first freshness parameter, the parameter is encapsulated in a type-length value format, and the tag value is set to a preset value specifically used to identify the first-generation network. This preset value is represented by a specific field defined by the protocol to ensure that only the first-generation network element can recognize and process it, thereby isolating the second-generation network element from access.

[0112] In one embodiment, the encapsulated first freshness parameter is transmitted on the interface to a target-side core network control plane element, such as a mobility management entity, via a dedicated signaling field. After recognizing the tag value, the mobility management entity directly transmits the encapsulated parameter without attempting to parse the content. This transmission process utilizes the forwarding rules of the signaling protocol to avoid parameter exposure and improve the confidentiality of the parameter during cross-network transmission.

[0113] Specifically, the target-side core network control plane network element will continue to forward the transparent encapsulation parameters to the second-generation access network, such as the evolved Node base station. After recognizing the tag value, the evolved Node base station will directly discard the encapsulation parameter and will not be able to parse the content of the first freshness parameter. This discarding mechanism is based on the tag filtering rules configured by the network element to prevent unauthorized access to the actual value of the parameter, thereby enhancing the security isolation of the overall key derivation.

[0114] In one possible implementation, the second-generation access network uses only its own parsable second freshness parameter in the subsequent key derivation process. This second freshness parameter also adopts the type length value format but has a different tag value. The first freshness parameter is isolated because of the tag value identification and cannot be obtained by the second-generation access network. This isolation ensures that the key derivation only depends on the parameters of their respective domains, avoiding security vulnerabilities caused by cross-generational mixing.

[0115] S32, the second freshness parameter is encapsulated in TLV format, and the tag value is a value dedicated to the second generation. The source-side core network control plane network element and the first-generation access network only transmit the parameter transparently without parsing the actual content of the parameter.

[0116] After generating the second freshness parameter, the source-side core network control plane element encapsulates it using a tag-length value format. The tag value is a dedicated numerical value for identifying the second-generation parameter, the length field indicates the parameter content length, and the value field carries the actual parameter content. The encapsulated second freshness parameter is sent to the first-generation access network element via an interface message. Upon receiving the parameter, the first-generation access network element directly recognizes the tag value as second-generation specific and performs transparent transmission, forwarding only the complete parameter content without parsing the value field. The first-generation access network element then forwards the transparently transmitted second freshness parameter to the user equipment via an air interface message. Upon receiving the parameter, the user equipment identifies and parses the value field content based on the preset second-generation specific tag value to obtain the actual meaning of the second freshness parameter. Throughout the transmission path, the first-generation access network element only performs forwarding operations on the second freshness parameter, ensuring that the parameter content generated by the source-side core network control plane element remains unparsed at the first-generation access network element.

[0117] For example, after the source-side core network control plane network element generates the second freshness parameter, the network element places the parameter into a tag length value format, where the tag value is preset to a value dedicated to the second generation, used to distinguish different generation parameter types. This is done to ensure that subsequent network elements can quickly identify and determine the processing method, thereby improving the security and exclusivity of parameter transmission and bringing the useful effect of preventing attacks caused by misuse.

[0118] Specifically, the length field records the number of bytes in the value field, while the value field stores the original data of the parameter. This encapsulation process is completed byte by byte through an internal buffer. First, the tag value byte is written, then the length field byte is written, and finally the value field content is appended to form a complete information element.

[0119] In one embodiment, when the source-side core network control plane element completes encapsulation, the parameter is embedded in the dedicated information element field of the interface message and sent to the first-generation access network element via the link. After receiving the message, the first-generation access network element first reads the tag value. If the tag value matches the second-generation dedicated value, it directly copies the entire information element to the output buffer without accessing the part indicated by the length field, thereby achieving transparent transmission. The purpose of this method is to isolate the processing logic of different generations, avoid the first-generation network element from misoperating the second-generation parameter, and bring the useful effect of enhancing system compatibility and anti-interference capability.

[0120] For example, in actual transmission scenarios, interface messages use standard protocol formats and encapsulate parameters as optional fields. First-generation access network elements only check the tag values ​​without expanding the value range through the protocol stack parser. The reason for doing so is to maintain the independence between network elements, ensure that the integrity of parameters is not tampered with by intermediate nodes, and thus provide more reliable end-to-end protection.

[0121] In one possible implementation, the first-generation access network element places the transparently transmitted parameters into the corresponding fields of the air interface message and forwards them to the user equipment. After receiving the message, the user equipment uses its built-in protocol parsing module to first match the tag value with the preset second-generation dedicated value, then reads the length field to obtain the value field size, and then extracts the value field content for decoding to restore the actual meaning of the second freshness parameter. The purpose of this processing is to enable the terminal to correctly use the parameters for security verification, thereby improving the overall network authentication efficiency.

[0122] Specifically, the parsing process of user equipment involves reading byte by byte. First, the tag value is verified, and then irrelevant parts are skipped and the value field is accessed directly based on the length field. The reason for this mechanism is to adapt to the coexistence environment of multiple generations of networks and ensure that parameters are only interpreted on the target entity, thereby reducing the potential risk of leakage.

[0123] In one embodiment, the entire transmission path emphasizes the forwarding operations of the first-generation access network elements, involving only message copying and routing selection, without any decoding or modification of the value domain. This is done to maintain the parameters in an unparsed state, starting from the source core network control plane elements and ending at the user equipment, thus providing a useful effect of enhanced privacy protection and prevention of replay attacks.

[0124] For example, in a multi-element link, the first-generation access network element acts as an intermediate bridge, only executing port forwarding logic and routing to the next hop according to the message header, while the parameter content remains in an encrypted encapsulated form. The reason for this approach is to isolate the functions of different generations in a layered manner, prevent cross-interference, and thus support smooth network evolution and compatibility.

[0125] It should be noted that this transparent transmission mechanism is implemented by predefining the range of tag values ​​in the protocol specification. The first-generation network element hard-codes the ignoring of unknown tags in the firmware, thereby ensuring compatibility and bringing the useful effect of long-term system stability.

[0126] In one possible implementation, when connected states are involved, the second freshness parameter can be generated based on the downlink counter, but the same encapsulation and pass-through process is still used during transmission. This serves to unify parameter management, reduce mutation points, and bring about the useful effect of simplifying operation and maintenance.

[0127] Specifically, in idle state switching scenarios, parameters are converted to random number form, but the encapsulation tag value remains consistent. The first-generation network element still only transmits information transparently, thus forming a complementary support with the connected state and jointly improving the security of cross-generation switching.

[0128] S41, the first generation mobile communication system is a 5G system, the second generation mobile communication system is a 4G system, the source side core network control plane element is AMF, the target side core network control plane element is MME, the first generation core key is selected from at least one of KAMF and KSEAF, and the first freshness parameter and the second freshness parameter are transmitted in isolation through the relevant signaling fields of the N26 interface and NG interface, respectively.

[0129] Upon receiving a handover request notification, the source-side core network control plane element generates a first freshness parameter. This first freshness parameter is transmitted to the user equipment (UE) via next-generation radio access network (NGR) related signaling fields, but is not sent to the target-side core network control plane element via an interface. The source-side core network control plane element uses the first-generation core key and the first freshness parameter to generate a first mobile communication system master key (MHS master key) through a key derivation function. This first MHS master key is sent to the target-side core network control plane element via an interface, while the first-generation core key is not sent to the target-side core network control plane element. The target-side core network control plane element generates a second freshness parameter, which is transmitted to the UE via an interface and NRG related signaling fields, but is not sent to the source-side core network control plane element. The target-side core network control plane element uses the first MHS master key and the second freshness parameter to generate a second MHS master key using the same key derivation function. The UE synchronously uses the first MHS master key and the second freshness parameter to generate the second MHS master key, ensuring consistency among the three key parties.

[0130] For example, during the process of generating the first freshness parameter after the source-side core network control plane element receives the handover request notification, this parameter can be used as a non-access stratum downlink counter to ensure the uniqueness of the key. This can prevent security risks caused by key reuse.

[0131] Specifically, the first freshness parameter is transmitted to the user equipment through signaling fields of the next-generation radio access network, such as the handover preparation message. This transmission method is limited to the 5G domain, which avoids the parameter being leaked to the 4G side, thereby maintaining the secure isolation of the source system and enhancing the overall handover security.

[0132] In one possible implementation, if the handover request notification includes wireless measurement data of the user equipment, the source network element will generate parameters based on this data to ensure that the parameters match the current connection state. This provides a more accurate basis for key derivation and reduces the risk of subsequent synchronization failures.

[0133] For example, when the source-side core network control plane element generates the first mobile communication system master key using the first-generation core key and the first freshness parameter through a key derivation function, the function can be a key derivation process based on a hash message authentication code, wherein the input includes the core key as the root key and the freshness parameter as the salt value. This generation method ensures the randomness and strength of the key.

[0134] Specifically, the generated key is sent to the target network element only through the relocation request message of the N26 interface, while the core key itself is not transmitted. This can block the target system from accessing the source core security, which is beneficial for achieving reverse isolation and preventing the spread of potential cross-generational attacks.

[0135] In one possible implementation, the user device mirrors this process, using the locally stored core key to independently generate the same master key, which provides the convenience of three-way synchronization and improves the seamlessness of switching.

[0136] For example, after the target-side core network control plane element generates the second freshness parameter, it transmits it to the user equipment through the N26 interface and next-generation radio access network signaling fields such as parameter forwarding messages. This isolated transmission ensures that the parameter is limited to circulation within the 4G domain and is not exposed to the source-side network element, thereby maintaining a two-way security boundary.

[0137] Specifically, the second freshness parameter can be a dynamic value based on the non-access stratum uplink count, which is generated and used immediately for subsequent derivation. This enhances the freshness of the key and helps resist replay attacks.

[0138] In one possible implementation, if the transmission path involves relaying through source-side network elements, the relay only processes signaling and does not parse parameter content, which can provide stronger privacy protection and reduce the possibility of information leakage.

[0139] For example, during the process of generating the second mobile communication system master key using the first mobile communication system master key and the second freshness parameter through the same key derivation function, the same hashing mechanism is repeatedly used to ensure output consistency. The user equipment synchronously executes the same derivation to achieve consistency of the three-party keys of AMF, MME and user equipment.

[0140] Specifically, this synchronization mechanism allows all key configurations to be completed before the switchover, which eliminates the data exposure window and helps ensure business continuity, especially in latency-sensitive scenarios.

[0141] In one possible implementation, the generated second master key is further used to derive encryption and integrity subkeys for immediate activation of 4G security, which enables rapid protection activation and enhances user privacy and system robustness.

[0142] This invention also provides a method for security management before the handover from 5G to 4G systems, which may specifically include: Step S201: Based on the deployment location and coverage data of edge computing nodes, combined with user movement trajectory prediction data and historical handover pattern records, by analyzing the behavioral characteristics of users in the overlapping area of ​​5G and 4G networks and incorporating the generation of source domain freshness parameters and the update of freshness counters, a pre-established prediction model is used to estimate the handover event that is about to occur, and the potential handover time point and target network type judgment result are obtained, while binding the source domain identifier mark.

[0143] Based on the deployment location and coverage data of edge computing nodes, the overlapping area to which the user's current location belongs is determined. User movement trajectory prediction data and historical handover records are used to obtain the user's behavioral characteristics within the overlapping area. The freshness counter is updated based on the behavioral characteristics and the source domain freshness parameter. A pre-established prediction model is used to process the updated freshness counter and behavioral characteristics to obtain potential handover time points. If the potential handover time point matches the current location's coverage data, the target network type is determined. The handover event result is bound based on the target network type and the source domain identifier. The source domain identifier corresponding to the handover event is determined through the deployment location of the edge computing nodes.

[0144] Specifically, edge computing nodes are deployed near base stations, each with a coverage radius of approximately 500 meters. They collect user location data and signal strength, and fuse historical user movement trajectory prediction data using a Kalman filtering algorithm. For example, using the GPS coordinate sequence of the past 10 seconds to predict the trajectory for the next 30 seconds, the trajectory prediction accuracy reaches 92.3%. Simultaneously, historical handover pattern records are integrated, such as the user switching from 5G to 4G in 80% of past instances along the same path. The system analyzes user behavior characteristics in the overlapping area of ​​5G and 4G networks, including an average signal attenuation rate of -3.2 dB / s and a 0.65-fold increase in handover probability at a moving speed of 40 km / h. Clustering algorithms such as K-means are used to categorize behavior into high-speed straight-line and low-speed turning types. A source domain freshness parameter is incorporated, defined as exp... Where λ=0.1, Δt is the data freshness difference. If Δt exceeds 5 seconds, the freshness is lower than 0.606, and the weight is reduced accordingly. At the same time, the freshness counter is updated to the current weighted average count to ensure that the data freshness is higher than 0.8 before it is used for prediction. A pre-built LSTM prediction model is used. The input features include trajectory vector, RSRP difference, and freshness-weighted behavioral features. The model is trained on 10,000 historical records and outputs the potential handover time point, such as a handover in the next 15.7 seconds, and the target network type judgment result, which is a probability of 0.87 for handover to 4G. At the same time, the source domain identifier is bound, such as the edge node ID "ECN-045". The whole process is calculated in real time at the edge node with a latency of less than 10 ms, forming a closed-loop logic chain: trajectory prediction drives behavioral analysis, freshness ensures data reliability, and model inference and binding results optimize handover decisions, reducing the handover failure rate by up to 75% and improving network continuity.

[0145] Step S202: Based on the potential handover time point and target network type judgment result accompanied by source domain identifier marking, the handover security context information of the corresponding user is obtained from the 5G core network in advance, and the 5G core key is extracted synchronously. Parameter conversion processing is performed on the obtained context data and 5G core key, while key derivation path separation and temporary key intermediate value discarding are performed. The security parameters of the 5G network are adjusted to a 4G network compatible format and incorporated into freshness parameter binding to form a converted security context dataset containing isolated key components.

[0146] Based on the potential handover time point and target network type, combined with the source domain identifier, the handover result is determined to trigger the early acquisition operation. Handover security context information is obtained from the 5G core network, and the 5G core key is extracted synchronously to obtain the original security context dataset. Parameter transformation processing is performed on the original security context dataset to obtain the transformed parameter dataset. Key derivation path separation is performed on the transformed parameter dataset to separate independent key derivation paths. Temporary key intermediate values ​​are discarded for the separated independent key derivation paths to obtain cleaned key components. Security parameters are adjusted to a 4G network-compatible format based on the cleaned key components and bound with freshness parameters to obtain a bound security context dataset. The key components are isolated from the bound security context dataset to form a transformed security context dataset.

[0147] Specifically, in handling the security context transition from 5G to 4G network, the system first determines the potential handover time and target network type. It automatically analyzes whether the user equipment may switch from 5G to 4G network at a specific time (e.g., 14:30:00 on October 10, 2023). Combining the source domain identifier (e.g., 5G core network ID "5GCN_001"), the system calls the API interface through the network management platform to obtain the corresponding user's handover security context information from the 5G core network in advance. This information includes the user identity identifier (IMSI: 460001234567890) and the current session key (e.g., K_5G=0xA1B2C3D4). The system also extracts the 5G core key (K_SEAF=0xE5F6G7H8) simultaneously. This process ensures data security through TLS encrypted transmission. Next, based on the acquired context data and 5G core key, the system automatically performs parameter conversion processing, using the SHA-256 algorithm to hash K_5G and K_SEAF to generate intermediate values ​​(e.g., Hash_K=0x1A2B3C4D). Simultaneously, it performs key derivation path separation, using the HMAC-SHA-256 algorithm to separate the key components suitable for 4G (e.g., K_4G=0x5E6F7G8H), and discards the temporary key intermediate value (e.g., Hash_K) to prevent leakage. The separation process logs the input and output values ​​of each operation for auditing purposes. Subsequently, the system adjusts the 5G network security parameters to a 4G network compatible format. Specifically, it aligns K_4G with the 128-bit key length required by the 4G network and incorporates freshness parameters (e.g., timestamp 20231010143000 and random number Nonce=0x12345678) for binding, generating the final key (e.g., K_Final=0x9A8B7C6D) through an XOR operation. Finally, a transformed security context dataset is generated, containing isolated key components (such as K_Final and auxiliary parameters Nonce), and stored in the security module using AES-128 encryption to ensure data isolation and integrity. A log system records the success status and timestamp of each transformation, forming a complete audit chain. This process is implemented through automated scripts and encryption algorithms to ensure the security of the 5G to 4G handover. Logically, it forms a tight chain through key derivation and parameter binding, while also being closely linked to network handover services to ensure user session continuity.

[0148] Step S203: If the converted security context dataset meets the preset format verification standard and the source domain freshness parameter is fully bound, the converted security context dataset is stored in the cache area of ​​the edge computing node. At the same time, during the storage process, the security sandbox isolation mechanism is enabled and the isolation sandbox execution environment is run. The cached data is encrypted and encapsulated with 5G core key isolation to generate a protected security context storage unit embedded with the source domain freshness parameter generation record.

[0149] Obtain the transformed security context dataset and associate it with the source domain freshness parameter. Perform a format validation standard comparison on the dataset to determine if the validation result passes. If it passes, retain the dataset; otherwise, mark the dataset and terminate subsequent processing. Check the complete binding status of the source domain freshness parameter. If it is completely bound, continue processing and mark the dataset; otherwise, trigger the parameter completion process and rebind. Activate the isolated execution environment using a security sandbox mechanism, and load the validated and completely bound dataset into the cache area of ​​the edge computing node for storage. Apply data encryption and encapsulation to the dataset stored in the cache area through the isolated execution environment. Combine the 5G core key to perform key isolation processing on the encrypted and encapsulated dataset to obtain a protected storage unit. Embed the source domain freshness parameter in the protected storage unit and generate the corresponding freshness generation record.

[0150] Specifically, during the transformation and storage of the security context dataset, the system first checks whether the transformed dataset conforms to the preset format verification standard. It automatically calls a JSON Schema-based verification tool. Assuming the dataset contains fields such as user ID, timestamp, and security policy, and the verification rule requires the timestamp format to be "YYYY-MM-DD HH:MM:SS", if the verification finds a timestamp of "2023-10-15 14:30:00", it conforms to the standard, and the verification pass rate must reach 100%. Otherwise, an error log is triggered, and the transformation operation is rolled back. Next, the system verifies the integrity of the source domain freshness parameter binding. It calculates the parameter hash value using the SHA-256 algorithm. Assuming the parameter value is "Freshness_2023_10_15_12345", the hash result is a fixed 64-byte length. If the bound parameter is missing, the hash comparison fails, and the system automatically triggers a parameter completion mechanism. Subsequently, eligible datasets are stored in the edge computing node cache area, with a cache capacity of 10GB. The LRU (Least Recently Used) algorithm is used to manage the cache space, and the data write speed is controlled at 50MB / s to avoid overload. A secure sandbox isolation mechanism is also enabled. The system builds an isolated environment based on Linux Namespace technology, restricting cached data access permissions to only specific process IDs (e.g., PID 1024). During the execution of the isolated sandbox environment, the system encrypts and encapsulates the cached data using the AES-256 algorithm with a 32-byte key length. Combined with 5G core key isolation technology, the key is updated every 24 hours to ensure encryption strength. The encrypted data block size is 128KB. Finally, a protected security context storage unit is generated, embedding the source domain freshness parameter generation record. The system uses a timestamp and parameter value to form a unique identifier, such as "2023-10-15_Freshness_12345", and stores it in a distributed database. A redundancy backup factor of 3 is set to ensure data reliability. After the storage unit is generated, the system automatically triggers a consistency check, calculating the CRC32 checksum of the storage unit (e.g., 0x4A17B156). If the check passes, a successful storage log is recorded; otherwise, a rollback mechanism is triggered. Through the above process, a complete logical chain from checksum to storage is formed, ensuring data security and consistency.

[0151] Step S204: Match potential switching time points based on the real-time trigger signal of the switching event, obtain the cached security context storage unit in the edge computing node, extract the security parameter content in it through decryption operation and verify the freshness counter update status, and determine that the set of context information that can be used for the current switching process includes the isolated key component and the source domain identifier.

[0152] The system captures handover signals in real-time, analyzes their characteristics, and determines the potential time frame range. Based on this range, it extracts the corresponding security context storage unit from the edge computing node's cache. A pre-defined decryption mechanism is used to process the extracted security context storage unit, obtaining its security parameters. For each parameter, the freshness counter data is checked to determine if the update status meets pre-defined conditions. If it does, the parameter is retained. If the freshness counter update status does not meet the conditions, a backup security context storage unit is retrieved from the cache, and the decryption process is repeated until the parameters meet the conditions. The parameters meeting the conditions are categorized and sorted to select a context set, separating the key components and source domain identifiers. Based on the separated key components and source domain identifiers, a complete set of context information suitable for the current handover process is constructed.

[0153] Specifically, when matching potential switching time points with real-time trigger signals for switching events in edge computing nodes, the system first compares the current network clock with the timestamp of the switching signal using a timestamp synchronization mechanism. For example, if the current time is 2023-10-10 14:30:00.123 and the timestamp of the switching signal is 2023-10-10 14:30:00.100, the time difference is 0.023 seconds, which is less than the preset threshold of 0.05 seconds, thus identifying it as a potential switching time point. Next, the system accesses the cached security context storage unit within the edge node and uses an indexing algorithm (such as hash table lookup) to locate the cached data with storage unit ID SCU_001. This data is 256KB in size and contains encrypted security parameters. Subsequently, the system calls the AES-256 decryption algorithm, using a pre-shared key (32 bytes long) to decrypt the storage unit data and extract the security parameters, including the freshness counter value (currently 1001) and key components. When verifying the freshness counter, the system compares it with historical records (last time 1000), confirms the counter increments by 1, indicating an update status, and determines the data is valid. Finally, the system selects a set of context information usable for the current handover process, stores the key component (128 bits long) and the source domain identifier (value SRC_DOMAIN_01) in isolated locations, and generates a checksum (e.g., 0xA1B2C3D4) using the SHA-256 algorithm to ensure data integrity. If the source domain identifier does not match the target domain, the system automatically triggers a backup context query mechanism, calling the backup storage unit SCU_002 to repeat the above decryption and verification process, forming a closed-loop logic to ensure uninterrupted handover. Through this method, the system completes context matching and verification within milliseconds, ensuring handover efficiency.

[0154] Step S205: The extracted context information set is tested for integrity and validity using a preset verification algorithm. At the same time, the consistency of key derivation path separation and the traces of temporary key intermediate value loss are checked. If the test results meet the preset threshold requirements and the source domain freshness parameter isolation verification is passed, the information set is transmitted to the access device of the target network to complete the application of security context during the handover process and refresh the freshness counter.

[0155] For contextual information, a pre-defined verification algorithm is used for preliminary processing. This involves scanning the structure and content of the information set to determine if it conforms to pre-defined format and integrity standards, yielding preliminary verification results. Based on these results, a pre-defined verification mechanism is invoked for integrity checks and validity verification. Key fields in the contextual information are compared; if the comparison result matches a pre-defined threshold, the information set passes integrity checks and validity verification. Following the integrity and validity verification results, a consistency verification process is executed for key derivation and path separation. The separation record of the key derivation path is obtained; if the separation record matches a pre-stored template, the path separation meets the requirements. Based on the path separation verification results, for temporary keys and intermediate value discarding, the temporary key processing log is scanned to obtain intermediate value discarding traces. If the discarding traces are complete and without anomalies, the temporary key processing meets security standards. Based on the temporary key processing verification results, for freshness parameters and isolation verification, the freshness parameter data of the source domain is extracted and compared using pre-defined isolation verification logic. If the parameter data matches the isolation standard, the freshness parameter verification passes. Based on the results of the freshness parameter verification, the update mechanism of the target network access device is triggered for counter updates. By sending an update command to the device, the updated counter status is obtained, and the application of the security context and the completion of the counter refresh are determined.

[0156] like Figure 7As shown, the complete process of edge computing nodes performing prediction and security context preprocessing in a 5G to 4G handover scenario includes the following steps: In S201, the edge computing node, based on its deployment location, user movement trajectory prediction data, and historical handover patterns, uses an LSTM prediction model to calculate potential handover time points and target network types, and binds source domain identifiers. In S202, the security context required for handover is obtained in advance from the 5G core network, and key derivation path separation and temporary key intermediate value discarding operations are performed to form a transformed security context dataset. In S203, the transformed dataset is stored in the edge node cache area and encrypted and encapsulated using a secure sandbox isolation mechanism. Subsequently, the system continuously monitors the handover trigger signal. Upon receiving the trigger signal, in S204, the cached security context storage unit is obtained based on the handover trigger signal, and the freshness counter status is verified. After verification, in S205, a verification algorithm is used to check the integrity and validity. If successful, the data is transmitted to the target network access device to refresh the freshness counter. If the verification fails, error handling is performed to discard the invalid context, and the process returns to S202 to re-obtain the security context. This process, through predictive mechanisms and secure sandbox isolation, enables advance preparation and secure transmission of security context switching, reducing switching latency and improving security.

[0157] According to another embodiment of the present invention, a security management system is provided before switching from a second mobile communication system to a first mobile communication system, comprising: The first generating device is used to cause the source-side core network control plane network element to generate a first intermediate master key based on the second mobile communication system core key and the first freshness parameter through a key derivation function. The first freshness parameter is generated only in the second mobile communication system and transmitted to the user equipment. The first mobile communication system cannot obtain the first freshness parameter. A transmitting device is used to cause the source-side core network control plane element to send the first intermediate master key to the target-side core network control plane element. The transmission of the first intermediate master key does not carry any second mobile communication system core key. The second generation device is used to cause the target-side core network control plane network element to generate a second master key based on the first intermediate master key and the second freshness parameter through the same key derivation function. The second freshness parameter is generated by the target-side core network control plane network element and is only transmitted to the user equipment. The second mobile communication system cannot obtain the second freshness parameter. The receiving device is configured to enable the user equipment to receive the first freshness parameter and derive the first intermediate master key based on the core key of the second mobile communication system before actually accessing the first mobile communication system, and then receive the second freshness parameter and derive the second master key based on the first intermediate master key, so that the user equipment has a complete security key system of the first mobile communication system when accessing the first mobile communication system.

[0158] The first freshness parameter includes: a downlink count of the second mobile communication system non-access stratum or a random number on the second mobile communication system side, which is transmitted to the user equipment through the second mobile communication system access network. The target-side core network control plane network element and the first mobile communication system access network cannot parse the actual value of the first freshness parameter. The second freshness parameter includes an uplink count of the first mobile communication system non-access stratum or a partial static identifier of the user equipment, which is transparently transmitted to the user equipment through the source-side core network control plane network element and the second mobile communication system access network. The source-side core network control plane network element only transmits the actual value of the second freshness parameter without parsing it.

[0159] The key derivation function includes: a key derivation function defined by the 3GPP standard, which uses a first function code when generating the first intermediate master key and a second function code different from the first function code when generating the second master key.

[0160] The first intermediate master key includes: both the first intermediate master key and the second master key are 256 bits in length. The target-side core network control plane network element derives the first mobile communication system non-access stratum encryption key, non-access stratum integrity key and access stratum core key based on the second master key.

[0161] The first freshness parameter includes: the first freshness parameter is encapsulated in a tag length value format, the tag value is a value specifically for identifying the second mobile communication system, and the target-side core network control plane network element directly transmits the value after recognizing the tag without being able to obtain the actual content of the parameter; the second freshness parameter is encapsulated in a tag length value format, the tag value is a value specifically for identifying the first mobile communication system, and the source-side core network control plane network element only transmits the value without parsing the actual content of the parameter.

[0162] Before the user equipment actually accesses the first mobile communication system, the process includes: the user equipment completing the derivation of the first intermediate master key and the second master key while still maintaining a connection with the access network of the second mobile communication system; the user equipment returning a key synchronization confirmation signal to the access network of the second mobile communication system; and after the handover is completed, the source-side core network control plane network element, the target-side core network control plane network element, and the user equipment destroy the first intermediate master key, retaining only the second master key and its derived keys.

[0163] The second mobile communication system is a 5G system, the first mobile communication system is a 4G system, the source-side core network control plane element is an access and mobility management function entity, the target-side core network control plane element is a mobility management entity, and the core key of the second mobile communication system is selected from at least one of the authentication anchor key and the access and mobility management function binding key.

[0164] According to another embodiment of the present invention, a system for security management before the handover from 5G to 4G is provided, the system comprising: The estimation device is used to estimate upcoming handover events based on edge computing node deployment location and coverage data, combined with user movement trajectory prediction data and historical handover pattern records. By analyzing user behavior characteristics in the overlapping area of ​​5G and 4G networks and incorporating source domain freshness parameter generation and freshness counter updates, it uses a pre-established prediction model to estimate potential handover time points and target network type judgment results, while binding source domain identifier tags. The extraction device is used to determine the source domain identifier by identifying the potential handover time point and target network type, obtain the handover security context information of the corresponding user from the 5G core network in advance, and simultaneously extract the 5G core key. The device performs parameter conversion processing on the obtained context data and 5G core key, and performs key derivation path separation and temporary key intermediate value discarding. The security parameters of the 5G network are adjusted to a 4G network compatible format and incorporated into freshness parameter binding to form a converted security context dataset containing isolated key components. The generation device is used to store the converted security context dataset in the cache area of ​​the edge computing node if the converted security context dataset meets the preset format verification standard and the source domain freshness parameter is completely bound. At the same time, during the storage process, a security sandbox isolation mechanism is enabled and an isolation sandbox execution environment is run. The cached data is encrypted and encapsulated with 5G core key isolation to generate a protected security context storage unit that embeds the source domain freshness parameter generation record.

[0165] Further, it includes: matching potential switching time points based on real-time trigger signals of switching events, obtaining cached security context storage units within edge computing nodes, extracting security parameter content from them through decryption operations and verifying the freshness counter update status, and determining that the set of context information available for the current switching process includes isolated key components and source domain identifiers.

[0166] Further, it includes: using a preset verification algorithm to detect the integrity and validity of the extracted context information set, while checking the consistency of key derivation path separation and the traces of temporary key intermediate value discarding. If the detection results meet the preset threshold requirements and the source domain freshness parameter isolation verification is passed, the information set is transmitted to the access device of the target network to complete the application of security context during the handover process and refresh the freshness counter update.

[0167] Obviously, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the spirit and scope of the embodiments of this application. Therefore, if these modifications and variations to the embodiments of this application fall within the scope of the claims of this application and their equivalents, this application also intends to include these modifications and variations.

Claims

1. A security management method before handover from a second mobile communication system to a first mobile communication system, characterized by, include: The source-side core network control plane network element generates a first intermediate master key based on the second mobile communication system core key and the first freshness parameter through a key derivation function. The first freshness parameter is only generated within the second mobile communication system and transmitted to the user equipment. The first mobile communication system cannot obtain the first freshness parameter. The source-side core network control plane element sends the first intermediate master key to the target-side core network control plane element. The transmission of the first intermediate master key does not carry any second mobile communication system core key. The target-side core network control plane element generates a second master key based on the first intermediate master key and the second freshness parameter through the same key derivation function. The second freshness parameter is generated by the target-side core network control plane element and is only transmitted to the user equipment. The second mobile communication system cannot obtain the second freshness parameter. Before actually accessing the first mobile communication system, the user equipment receives the first freshness parameter and derives the first intermediate master key based on the core key of the second mobile communication system. Then, after receiving the second freshness parameter, it derives the second master key based on the first intermediate master key, thereby enabling the user equipment to have a complete security key system of the first mobile communication system when accessing the first mobile communication system.

2. The method of claim 1, wherein, The first freshness parameter includes: The downlink count or random number on the second mobile communication system non-access layer is sent to the user equipment through the second mobile communication system access network. The target core network control plane network element and the first mobile communication system access network cannot parse the actual value of the first freshness parameter. The second freshness parameter includes the uplink count of the non-access layer of the first mobile communication system or a partial static identifier of the user equipment. It is transmitted to the user equipment through the source-side core network control plane network element and the access network of the second mobile communication system. The source-side core network control plane network element only transmits and does not parse the actual value of the second freshness parameter.

3. The method of claim 1, wherein, The key derivation function includes: The key derivation function defined by the 3GPP standard is adopted. When generating the first intermediate master key, a first function code is used, and when generating the second master key, a second function code different from the first function code is used.

4. The method of claim 1, wherein, The first intermediate master key includes: Both the first intermediate master key and the second master key are 256 bits in length. The target-side core network control plane network element derives the first mobile communication system non-access stratum encryption key, non-access stratum integrity key and access stratum core key based on the second master key.

5. The method of claim 1, wherein, The first freshness parameter includes: The first freshness parameter is encapsulated in a tag length value format. The tag value is a value specifically for identifying the second mobile communication system. After the target side core network control plane network element recognizes the tag, it directly transmits the value without being able to obtain the actual content of the parameter. The second freshness parameter is encapsulated in a tag length value format. The tag value is a value specifically for identifying the first mobile communication system. The source-side core network control plane network element only transmits the value without parsing the actual content of the parameter.

6. The method of claim 1, wherein, The user equipment includes the following components before it actually accesses the first mobile communication system: The user equipment completes the derivation of the first intermediate master key and the second master key while still maintaining a connection with the second mobile communication system access network; The user equipment returns a key synchronization confirmation signaling to the second mobile communication system access network; After the switchover is completed, the source-side core network control plane network elements, the target-side core network control plane network elements, and the user equipment destroy the first intermediate master key, and only retain the second master key and its derived keys.

7. The method of claim 1, wherein, The second mobile communication system is a 5G system, the first mobile communication system is a 4G system, the source-side core network control plane network element is an access and mobility management function entity, the target-side core network control plane network element is a mobility management entity, and the core key of the second mobile communication system is selected from at least one of the authentication anchor key and the access and mobility management function binding key.

8. A method for 5G to 4G system handover front security management, characterized by, The method includes: Based on edge computing node deployment location and coverage data, combined with user movement trajectory prediction data and historical handover pattern records, by analyzing user behavior characteristics in the overlapping area of ​​5G and 4G networks and incorporating source domain freshness parameter generation and freshness counter updates, a pre-established prediction model is used to estimate upcoming handover events, obtain potential handover time points and target network type judgment results, and bind source domain identifier tags. By judging the potential handover time point and target network type along with the source domain identifier, the handover security context information of the corresponding user is obtained from the 5G core network in advance, and the 5G core key is extracted simultaneously. The obtained context data and 5G core key are processed by parameter conversion, while key derivation path separation and temporary key intermediate value discarding are performed. The security parameters of the 5G network are adjusted to a 4G network compatible format and incorporated into freshness parameter binding to form a converted security context dataset containing isolated key components. If the converted security context dataset meets the preset format verification standard and the source domain freshness parameter is fully bound, the converted security context dataset will be stored in the cache area of ​​the edge computing node. At the same time, during the storage process, a security sandbox isolation mechanism will be enabled and an isolation sandbox execution environment will be run. The cached data will be encrypted and encapsulated with 5G core key isolation to generate a protected security context storage unit that embeds the source domain freshness parameter generation record.

9. The method of claim 8, wherein, Further includes: Match potential switching time points based on real-time trigger signals of switching events, obtain the cached security context storage units within the edge computing node, extract the security parameter content from them through decryption operations and verify the freshness counter update status, and determine the set of context information that can be used for the current switching process, including isolated key components and source domain identifiers.

10. The method of claim 9, wherein, Further includes: The extracted context information set is tested for integrity and validity using a preset verification algorithm. At the same time, the consistency of key derivation path separation and the traces of temporary key intermediate value loss are checked. If the test results meet the preset threshold requirements and the source domain freshness parameter isolation verification is passed, the information set is transmitted to the access device of the target network to complete the application of security context during the handover process and refresh the freshness counter.