Air Interface Key Update During SRNC Relocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the HSPA+ radio communication system, the security of the air interface key is compromised during SRNC relocation, as Node B+, which is located in an unsafe environment, is vulnerable to malicious attacks if the key is not updated, allowing attackers to monitor and fake user communication.

Innovation Solution

A method and system for updating the air interface key in real time during SRNC relocation, where the serving radio network controller sends key information to the destination radio network controller, which updates the key to generate new integrity and ciphering keys, enhancing security by changing the keys even if the old ones are compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the air interface key is not updated during SRNC relocation, then the system complexity is reduced and the relocation process is simpler, but the security of the communication system is compromised allowing attackers to monitor and fake user communication

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by updating the air interface key before the SRNC relocation is completed. The target RNC receives the new key information from the source RNC in advance (in the relocation preparation phase), so that when relocation occurs, the security context is already updated. This prevents the security vulnerability that would exist if the old key were used after relocation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the relocation message itself as an intermediary carrier to transfer the new air interface key from the source RNC to the target RNC. The key information is embedded within the relocation preparation and execution messages, allowing secure key distribution without requiring a separate key management channel, thus balancing security enhancement with procedural simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If real-time key updating is implemented during SRNC relocation, then security against malicious attacks is improved, but the complexity of the relocation procedure increases

Engineering Contradiction:
Improvevulnerability to attacksVSAvoidrelocation procedure complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the key update function with the existing SRNC relocation procedure. The new air interface key is transmitted using the same message structures and signaling channels that already exist for relocation (e.g., relocation preparation message, relocation command message). This combination avoids creating a separate key management protocol, thereby reducing the overall complexity increase while still achieving real-time key updating.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameter being transmitted during relocation from just the old key material to include new key material derived from the old key. By applying a key derivation function to generate a new air interface key based on the old key, the system updates the security parameter in real-time without requiring complete key re-generation or additional authentication procedures, thus limiting the complexity increase.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the air interface key is updated during relocation, then continuous monitoring by attackers is prevented, but additional signaling messages and processing are required

Engineering Contradiction:
Improveprotection against continuous monitoringVSAvoidrelocation signaling time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs the key update in the preparation phase of relocation, before the actual handover is executed. The source RNC calculates and sends the new key information to the target RNC in advance, allowing the target RNC to have the new key ready before the UE arrives. This preliminary key distribution minimizes the time the new key is needed during the critical handover moment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent effectively discards the old air interface key after the relocation is complete and recovers security by activating the new key. The old key material is no longer used for protecting the air interface after relocation, and the system transitions to using the new derived key. This key lifecycle management ensures that even if the old key was compromised, it cannot be used to decrypt post-relocation communications.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentEP2429227B1Method and system for updating air interface keys
Publication Date: 2016.06.15 ZTE CORP
  • EP2429227B1 patent drawingFigure 1~2
  • EP2429227B1 patent drawingFigure 3~4
  • EP2429227B1 patent drawingFigure 5~6

AI summary

A method for updating an air interface key is disclosed in the present invention. The method includes: after a serving radio network controller makes a decision to perform relocation, the serving radio network controller sending key information to a destination radio network controller directly or via a core network node; or the serving radio network controller notifying the core network node to send the key information to the destination radio network controller. The present invention further discloses a system for updating an air interface key, which includes a serving radio network controller and a destination radio network controller; the serving radio network controller is configured to, send key information to the destination radio network controller directly or via a core network node after deciding to perform relocation; or notify the core network node to send the key information after deciding to perform relocation. The present invention can improve the security of the system.