Anchor Node Key Transfer for Wireless Handover Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication systems, when a user equipment (UE) resumes connections with a new serving node, the transfer of security keys from the previous serving node to the new node is hindered if the security key is used by the previous node, as different nodes cannot use the same security key.

Innovation Solution

The proposed solution involves a method where the anchor node transfers a third key, different from the second key used by the anchor node, to the serving node during the resume procedure. This third key is used for secure communication between the UE and the serving node, ensuring compatibility without reusing the same security key across nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security key is transferred from the last serving node to the new serving node, then secure communication can be established between the UE and the new serving node, but the transfer is blocked when the last serving node is still using the same security key

Engineering Contradiction:
Improvesecure communicationVSAvoidkey transfer
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security key is segmented into two parts: the original security key kept by the last serving node for its ongoing communications, and a derived security key generated by the UE using a key derivation function. This segmentation allows both nodes to have the security key they need without conflict, as they use different key material.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of the security key by deriving a new key from the original key using a key derivation function with a specific seed (including the new serving node's identity). This parameter transformation creates a new security key that is cryptographically related to but distinct from the original, enabling transfer without compromising the last serving node's security.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If the same security key is reused across different serving nodes, then key management is simplified, but security is compromised as different nodes cannot use the same security key

Engineering Contradiction:
Improvekey managementVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The UE performs preliminary key derivation before communication with the new serving node begins. By pre-computing the derived security key using the new serving node's identity and transmitting it along with the context information, the system prepares the security credentials in advance, avoiding the need for complex real-time key management during handover.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The derived security key acts as an intermediary between the original security key and the communication requirements of the new serving node. It bridges the gap by being cryptographically derived from the original key (maintaining security relationships) while being distinct enough to allow the new node to use it independently without conflicting with the last serving node's key usage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If a new security key is derived and transferred during resume procedure, then compatibility between UE and new serving node is ensured, but the key derivation and transfer process becomes more complex

Engineering Contradiction:
ImprovecompatibilityVSAvoidkey derivation process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The UE autonomously performs the key derivation operation itself without requiring the last serving node to generate or manage the derived key. The UE uses its stored original security key and the new serving node's identity to self-generate the derived key, then includes it in the context transfer request. This self-service approach simplifies the overall system architecture by eliminating the need for the last serving node to support key derivation functionality.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4218276B1A method for key transfer
Publication Date: 2025.04.09 ZTE CORP
  • EP4218276B1 patent drawingFigure 1~2
  • EP4218276B1 patent drawingFigure 3
  • EP4218276B1 patent drawingFigure 4

AI summary

A wireless communication method for use in an anchor node is disclosed. The method comprises receiving, from a serving node, a context request message associated with a wireless terminal, wherein a first key and a first next hop chaining count are transmitted to the wireless terminal in a previous connection between the anchor node and the wireless terminal and wherein a second key determined based on the first key and the first next hop chaining count is used by the anchor node, and transmitting, to the serving node, a context response message comprising a third key which is different from the second key and a second next hop chaining count.