AEAD Mobility Security Contexts with Dynamic Algorithm Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communications systems face issues during UE mobility scenarios and dual connectivity deployments due to differing security contexts when UEs move between network entities that support and do not support AEAD algorithms, leading to performance degradation and compatibility issues.

Innovation Solution

Implementing AEAD algorithms and modes during mobility scenarios and dual connectivity deployments, ensuring consistent security contexts by selecting compatible algorithms and modes across network entities, such as RAN nodes and AMFs, to maintain uniform security and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If AEAD algorithms are implemented during mobility scenarios, then security consistency is improved, but compatibility issues arise when UEs move between network entities with different AEAD support

Engineering Contradiction:
Improvesecurity consistencyVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies parameter changes by dynamically selecting between AEAD and non-AEAD algorithms based on the capability parameters of network entities. The UE and network entities exchange capability information and adjust the security algorithm parameters accordingly, switching between AEAD modes (e.g., AES-GCM, ChaCha20-Poly1305) and traditional algorithms (e.g., AES-128-CBC, SNOW 3G) to maintain compatibility while ensuring security consistency across different network configurations.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If AEAD algorithms are used for security protection, then authentication and encryption are improved, but performance degradation occurs during handover between network entities

Engineering Contradiction:
Improveauthentication and encryptionVSAvoidperformance during handover
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-establishing security contexts and caching security parameters (such as keys, algorithms, and capability information) before handover occurs. The network entities and UE prepare security contexts in advance during the connected state, so that when handover is needed, the security parameters are already available and can be applied immediately without performance degradation. This includes pre-derived keys and pre-configured security algorithms that can be quickly switched during mobility events.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple AEAD algorithms and modes are supported, then versatility is improved, but device complexity increases

Engineering Contradiction:
Improvealgorithm supportVSAvoidimplementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by implementing a dynamic algorithm selection mechanism that adapts to the capabilities of network entities. Instead of statically supporting all possible AEAD algorithms, the system dynamically negotiates the most appropriate algorithm based on exchanged capability information. The UE and network entities dynamically adjust their security parameters during connection establishment and handover, selecting from a set of supported algorithms (e.g., AEAD algorithms like AES-GCM, ChaCha20-Poly1305 and traditional algorithms) based on mutual capability, thereby reducing implementation complexity while maintaining versatility.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250234252A1Authenticated encryption with associated data (AEAD) modes during mobility scenarios
Publication Date: 2025.07.17 LENOVO UNITED STATES INC
  • US20250234252A1 patent drawing
  • US20250234252A1 patent drawing
  • US20250234252A1 patent drawing

AI summary

Various aspects of the present disclosure relate to using authenticated encryption with associated data (AEAD) algorithms for user equipment (UE) mobility scenarios and/or dual connectivity deployments. For example, the technology enhances or updates various mobility procedures (e.g., Xn or N2 handover) to enable communications between an NE and a UE that utilize AEAD algorithms and/or AEAD modes when establishing security contexts for or during the mobility procedures. Thus, a wireless communications system can utilize the benefits of AEAD without introducing issues when a UE moves between NEs (e.g., RAN nodes) that support different security contexts, among other benefits.