5G Base Station Key Negotiation for LTE Core Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of appropriate key generation and transmission methods for 5G base stations that access an LTE core network using an LTE base station, which compromises key security.

Innovation Solution

A key negotiation method and apparatus that involves a first base station obtaining a selected key generation capability, generating a first key parameter, and sending it to a second base station, which then forwards it to a terminal, allowing the first base station to generate a base key independently, ensuring the second base station cannot learn the base key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the 5G base station accesses the LTE core network by using an LTE base station, then network compatibility is improved, but key security deteriorates due to lack of appropriate key generation and transmission methods

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidkey security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The key generation process is segmented into distinct phases: capability negotiation phase where key generation capabilities are exchanged, key parameter generation phase where cryptographic parameters are created, and key distribution phase where keys are securely transmitted. This segmentation allows each phase to be optimized for security while maintaining network compatibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary mechanisms including a key generation capability negotiation protocol and intermediate key parameters that facilitate secure key exchange between 5G base stations and LTE core network. These intermediaries enable compatibility while preventing direct key exposure to the LTE base station.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the MeNB forwards SCG modification request from SeNB to UE and generates counter parameter, then key update capability is improved, but key security deteriorates as the MeNB can potentially access generated keys

Engineering Contradiction:
Improvekey update capabilityVSAvoidkey security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the key generation function from the MeNB (Master eNodeB) and relocates it to the 5G base station (gNodeB). The MeNB no longer generates keys but only forwards capability information and key parameters. This extraction eliminates the security vulnerability where the MeNB could access generated keys while maintaining key update capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The 5G base station performs self-service key generation using its own cryptographic capabilities and the counter parameter provided by the MeNB. The key generation process is autonomous and does not require the MeNB to generate or store the actual keys, thereby improving security while maintaining update capability.

Inventive Principle:
Principle #25Self-service

3Reliability

If the 5G base station generates base key independently, then key security is improved, but device complexity increases due to additional key generation and transmission procedures

Engineering Contradiction:
Improvekey securityVSAvoidkey generation and transmission procedures
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action through capability negotiation before key generation. The 5G base station and network side establish key generation capabilities and selected algorithms in advance through signaling messages. This preliminary configuration simplifies the actual key generation process by pre-determining cryptographic parameters and procedures, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3499834B1Key negotiation method and apparatus
Publication Date: 2021.12.01 HUAWEI TECH CO LTD
  • EP3499834B1 patent drawingFigure 1
  • EP3499834B1 patent drawingFigure 2
  • EP3499834B1 patent drawingFigure 3

AI summary

Embodiments of the present invention provide a key negotiation method and apparatus. The method includes: obtaining, by a first base station, a selected key generation capability, and generating a first key parameter based on the selected key generation capability; sending, by the first base station, the first key parameter to a second base station, where the first key parameter is forwarded by the second base station to a terminal; and obtaining, by the first base station, a second key parameter generated by the terminal, and generating a first base key based on the first key parameter and the second key parameter. The first base station independently generates the base key, and the second base station plays only a role of parameter transfer. In this way, it can be ensured that the second base station cannot learn of the base key generated by the first base station, thereby ensuring key security.