5G Handover Security Context Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G communication system faces challenges in ensuring secure data communication and integrity when user equipment (UE) hands over between 5G and LTE networks, requiring efficient security procedures to manage mobility and maintain network security.

Innovation Solution

A method is introduced that involves transmitting handover requests and security information between base stations, utilizing NAS security parameters to generate and transmit 5G security contexts, ensuring secure communication by managing security information and algorithms between the UE and the network entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security information is transmitted during handover between 5G and LTE networks, then network security and data integrity are improved, but communication efficiency and handover speed may deteriorate due to additional security procedures

Engineering Contradiction:
Improvenetwork securityVSAvoidhandover efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-establishing security contexts and algorithms in the target base station before the actual handover occurs. The target base station receives and stores security information from the source base station in advance, so that when handover happens, the security setup is already prepared and can be quickly activated without adding delay to the handover process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the mobility management device as an intermediary to facilitate secure communication during handover. The mobility management device coordinates between source and target base stations, managing the transmission and establishment of security contexts, which streamlines the security procedure and prevents it from becoming a bottleneck in the handover process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security contexts are established between UE and network entities during handover, then data communication security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedata communication securityVSAvoidsecurity procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex security context management functions from the user equipment and concentrates them in the network entities (base stations and mobility management device). The UE simply receives and uses security parameters provided by the network, while the network entities handle the generation, transmission, and management of security contexts, thereby reducing the computational burden and complexity on the UE.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the security context establishment process with the existing handover signaling procedures. Instead of treating security setup as a separate complex procedure, it integrates security context transmission and establishment into the handover request and handover acknowledgment messages, thereby reducing overall procedural complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If handover request includes security information transmission, then security management efficiency is improved, but message size and transmission overhead increase

Engineering Contradiction:
Improvesecurity management efficiencyVSAvoidmessage size
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential security parameters needed for handover (such as security context identifiers and key material) and transmits them separately from the main handover signaling. This selective extraction reduces the size of handover messages while ensuring that all necessary security information is conveyed for establishing secure communication.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11553383B2Apparatus and method for network security
Publication Date: 2023.01.10 SAMSUNG ELECTRONICS CO LTD
  • US11553383B2 patent drawing
  • US11553383B2 patent drawing
  • US11553383B2 patent drawing

AI summary

The present disclosure relates to a 5th generation (5G) or pre-5G communication system for supporting a higher data transfer rate beyond a 4th generation (4G) communication system, such as long-term evolution (LTE). According to various embodiments of the present disclosure, a security method of a mobility management apparatus of a second system in a wireless environment may comprise the steps of: receiving a handover request for a terminal connected to a first system; transmitting the handover request to a base station of the second system; and receiving a handover ACK including security information generated by the base station of the second system and transmitting the same to the first system.