Radio Base Station Key Generation for Handover Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cellular radio systems face challenges in maintaining secure communication during handovers and reconnection processes, as the same transformed key is shared among base stations, potentially allowing unauthorized access and increasing complexity.
Innovation Solution
A method is introduced to derive a unique radio base station key and Terminal Identity Token using data known to both the mobile station and the radio base station, employing Pseudo-Random Functions (PRF) or hash functions with existing cryptographic keys and cell-specific data, such as PhyCell_ID, to enhance security without additional signaling or components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the same transformed key K_eNB* is shared by all base stations in the to-be-prepared set, then handover recovery capability is improved, but security is worsened as any base station could masquerade as the mobile station
Solution Approach 1:
The patent segments the key derivation process by introducing base station-specific initial data (seed values) that are unique to each base station in the to-be-prepared set. This causes the PRF to generate different transformed keys for each base station, thereby segmenting the previously shared key into multiple unique keys. The segmentation resolves the contradiction by maintaining handover recovery capability (through preparation at multiple base stations) while eliminating the masquerade attack vulnerability (through unique keys at each base station).
Solution Approach 2:
The patent applies local quality by assigning different initial data (seed values) to different base stations based on their local identities (e.g., base station IDs, cell IDs). Each base station uses its own local characteristics to generate a unique transformed key, rather than using a common key. This local differentiation resolves the security issue while preserving the handover recovery function.
2Object-affected harmful factors
If unique transformed keys are generated for each base station using PRF with base station-specific initial data, then security is improved, but device complexity is worsened due to additional key management
Solution Approach 1:
The patent implements self-service by enabling base stations to autonomously generate their own unique transformed keys using the PRF function and their own base station-specific initial data. The source base station also autonomously determines and transmits the appropriate initial data to target base stations without requiring external key management infrastructure. This self-service approach improves security through unique keys while avoiding the complexity of centralized key management systems.
Solution Approach 2:
The patent employs a universal PRF (Pseudo-Random Function) that can serve multiple purposes: generating transformed keys for handover, ensuring security, and working with different base station identifiers. The same PRF mechanism is used across all base stations, providing a unified and simple key derivation approach that avoids the need for multiple different key management mechanisms, thereby reducing overall system complexity.
3Object-affected harmful factors
If base station-specific initial data is transmitted to target base stations, then key uniqueness is improved, but signaling overhead is worsened
Solution Approach 1:
The patent changes the parameter of initial data representation by using compact base station identifiers (such as base station IDs, cell IDs, or other short parameters) as the initial data for the PRF. These identifier parameters are inherently compact and require minimal signaling bandwidth. By transforming these compact parameters into unique keys through the PRF function, the patent achieves key uniqueness without proportionally increasing signaling overhead.
Solution Approach 2:
The patent transmits only the essential initial data (base station identifiers) required for key derivation, rather than transmitting complete key material or extensive authentication data. This partial action approach provides sufficient information for the target base station to generate the unique transformed key locally, minimizing the signaling overhead while achieving the security goal of unique keys.
Data Source
AI summary
A Terminal Identity Token is created for identifying a User Equipment (UE) connected to a radio base station in a radio system. The UE communicates with the radio base station via a secure communication associated with an existing cryptographic key. The Terminal Identity Token is created based on a physical cell identity of a target cell known to both the UE and the radio base station, the terminal identity, and the existing key. By using the Terminal Identity Token, a secure communication can be established and enhanced without having to provide for additional security network components or additional signaling.


