Authentication Key Storage Segmentation for Network Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In telecommunications networks, particularly in LTE environments, UE devices face challenges in managing authentication keys across multiple security contexts, leading to potential key collisions and authentication failures during handovers between different network technologies.
Innovation Solution
A method and system for managing security key architecture in UE devices, which involves generating and storing authentication keys in context-specific elementary files on a removable SIM or non-volatile memory, ensuring that keys from one security context do not overwrite those from another, by using adapter components to manage key storage and retrieval based on access technologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If authentication keys are stored in a common location for multiple security contexts, then storage simplicity is improved, but key collisions and authentication failures occur during handovers
Solution Approach 1:
The patent divides the storage location into context-specific elementary files within the SIM card, where each security context (e.g., GERAN, UTRAN, E-UTRAN) has its own dedicated file. This segmentation prevents key collisions by ensuring that authentication keys from different security contexts are stored in separate, isolated locations, thereby maintaining authentication reliability during handovers between different network technologies.
2Adaptability or versatility
If multiple authentication procedures are negotiated for different network technologies, then network compatibility is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal authentication management mechanism that handles multiple security contexts through a common adapter layer. This adapter component provides multi-functional support for different network technologies (GERAN, UTRAN, E-UTRAN) by uniformly managing key storage and retrieval operations across context-specific files, thereby reducing the apparent complexity for the upper layers while maintaining broad network compatibility.
Solution Approach 2:
The patent introduces an adapter component as an intermediary between the authentication functions and the key storage mechanisms. This adapter manages the complexity of multiple authentication procedures by providing a unified interface that handles context-specific key retrieval automatically, allowing the system to support multiple network technologies without exposing the underlying complexity to the application layer.
3Reliability
If authentication keys are stored in removable SIM card, then security and flexibility are improved, but key management complexity across multiple contexts increases
Solution Approach 1:
The patent segments the SIM card storage into context-specific elementary files, where each file is dedicated to a particular security context (GERAN, UTRAN, E-UTRAN). This segmentation maintains security by isolating keys from different contexts while the adapter layer manages the complexity of accessing the appropriate file based on the current security context, thereby preventing key management errors without compromising security.
Data Source
AI summary
A user equipment (UE) device that is able to engage in multiple security contexts contains a key generator to generate one or more authentication keys for authentication of the UE device in a particular security context and a component configured to facilitate storing of the authentication keys in a subscriber identity module (SIM) if an elementary file (EF) structure for the particular security context is available in the SIM and to facilitate storing of the authentication keys in a nonvolatile memory (NVM) of the UE device if the EF structure is not found in the SIM.


