Target Base Station Handover Key Update Indication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile networks, during handover procedures, there is a potential security risk as an attacker can forge a key if the source base station is compromised, leading to insecure data transmission between the terminal device and the target base station.
Innovation Solution
The communication method involves the target base station determining, based on indication information and reference information, whether to update the access layer key with the terminal device, and sending appropriate indication to the source base station, ensuring secure key management and controlled key changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the source base station uses a forged key after being attacked, then the attacker can decrypt data transmitted between the terminal device and target base station, but the target base station cannot detect the key forgery
Solution Approach 1:
The patent applies preliminary action by having the target base station proactively send indication information to the source base station before the handover is completed, asking whether the source base station has updated the access layer key. This allows the target base station to prepare for potential key changes in advance, enabling it to detect and respond to forged keys before they compromise data transmission security.
Solution Approach 2:
The patent implements feedback by establishing a communication loop where the target base station sends inquiry information to the source base station about key updates, and the source base station responds with indication information about whether the key has been updated. This feedback mechanism enables the target base station to verify key authenticity and detect forged keys, resolving the security vulnerability while maintaining manageable key update procedures.
2Reliability
If the target base station always updates the access layer key during handover, then data transmission security is improved, but handover latency increases
Solution Approach 1:
The patent applies partial action by having the target base station selectively update the access layer key based on the indication information received from the source base station. Instead of always updating the key (excessive action), the target base station updates it only when the source base station confirms a key update has occurred, achieving necessary security improvements without unnecessary handover delays.
Solution Approach 2:
The patent changes the parameter of key update timing from a fixed always-update rule to a conditional update rule based on indication information. This parameter change allows the system to adapt key update behavior to actual security needs, reducing handover latency when key updates are not required while maintaining security when they are needed.
3Ease of operation
If the source base station does not indicate key update status, then the handover procedure is simpler, but the target base station cannot verify key authenticity
Solution Approach 1:
The patent extracts the key update status indication as a separate, dedicated information element that the source base station sends to the target base station. This extracted information allows the target base station to verify key authenticity without complicating the overall handover procedure, as the indication is carried within existing handover messaging structures in a standardized manner.
Data Source
AI summary
The present disclosure discloses a communication method and a device. The method is performed by a target base station and includes: receiving a handover request from a source base station, where the handover request includes a first key and first indication information, and the first indication information is used to indicate whether the first key is an updated key; and sending second indication information to the source base station based on the handover request, where the second indication information is used to indicate whether an access layer key between the target base station and a terminal device is an updated key. Using the embodiments of the present disclosure helps resolve a problem that a potential security risk exists in data transmitted between the terminal device and the target base station, and helps resolve a problem that a key change of the terminal device is not controlled by the base station.


