5G Base Station Key Negotiation for LTE Core Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a lack of appropriate key generation and transmission methods for 5G base stations that access an LTE core network using an LTE base station, which compromises key security.
Innovation Solution
A key negotiation method and apparatus that involves a first base station obtaining a selected key generation capability, generating a first key parameter, and sending it to a second base station, which then forwards it to a terminal, allowing the first base station to generate a base key independently, ensuring the second base station cannot learn the base key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the 5G base station accesses the LTE core network by using an LTE base station, then network compatibility is improved, but key security deteriorates due to lack of appropriate key generation and transmission methods
Solution Approach 1:
The key generation process is segmented into distinct phases: capability negotiation phase where key generation capabilities are exchanged, key parameter generation phase where cryptographic parameters are created, and key distribution phase where keys are securely transmitted. This segmentation allows each phase to be optimized for security while maintaining network compatibility.
Solution Approach 2:
The patent introduces intermediary mechanisms including a key generation capability negotiation protocol and intermediate key parameters that facilitate secure key exchange between 5G base stations and LTE core network. These intermediaries enable compatibility while preventing direct key exposure to the LTE base station.
2Adaptability or versatility
If the MeNB forwards SCG modification request from SeNB to UE and generates counter parameter, then key update capability is improved, but key security deteriorates as the MeNB can potentially access generated keys
Solution Approach 1:
The patent extracts the key generation function from the MeNB (Master eNodeB) and relocates it to the 5G base station (gNodeB). The MeNB no longer generates keys but only forwards capability information and key parameters. This extraction eliminates the security vulnerability where the MeNB could access generated keys while maintaining key update capability.
Solution Approach 2:
The 5G base station performs self-service key generation using its own cryptographic capabilities and the counter parameter provided by the MeNB. The key generation process is autonomous and does not require the MeNB to generate or store the actual keys, thereby improving security while maintaining update capability.
3Reliability
If the 5G base station generates base key independently, then key security is improved, but device complexity increases due to additional key generation and transmission procedures
Solution Approach 1:
The patent implements preliminary action through capability negotiation before key generation. The 5G base station and network side establish key generation capabilities and selected algorithms in advance through signaling messages. This preliminary configuration simplifies the actual key generation process by pre-determining cryptographic parameters and procedures, reducing operational complexity while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention provide a key negotiation method and apparatus. The method includes: obtaining, by a first base station, a selected key generation capability, and generating a first key parameter based on the selected key generation capability; sending, by the first base station, the first key parameter to a second base station, where the first key parameter is forwarded by the second base station to a terminal; and obtaining, by the first base station, a second key parameter generated by the terminal, and generating a first base key based on the first key parameter and the second key parameter. The first base station independently generates the base key, and the second base station plays only a role of parameter transfer. In this way, it can be ensured that the second base station cannot learn of the base key generated by the first base station, thereby ensuring key security.